
After receiving an SSL Certificate from a CA, the file format you receive may not match what your server or application requires. Apache needs PEM but you have PFX, or your Java application server requires JKS. This guide covers every OpenSSL command you need to convert SSL certificate files between all common formats.
Common SSL Certificate File Formats
Before converting, understand the differences between each format:
- PEM (.pem, .crt, .cer, .key) — Base64-encoded format, most widely used. Works with Apache, Nginx, HAProxy. Starts with
-----BEGIN CERTIFICATE----- - DER (.der, .cer) — Binary format used by Java and Windows
- PFX/PKCS#12 (.pfx, .p12) — Bundle containing Certificate + Private Key + Chain in one file. Used with IIS, Windows Server
- JKS (.jks) — Java KeyStore used with Tomcat and Java Application Servers
- P7B/PKCS#7 (.p7b, .p7c) — Contains multiple certificates without the Private Key. Used with IIS
Tip: Check the current format first with openssl x509 -in cert.crt -text -noout. If it displays text successfully, it is PEM format. If not, try the DER commands.
SSL File Formats and Web Server Compatibility
Use this quick-reference table to determine which format you need for your target platform before deciding on a conversion path.
| Web Server / Platform | Supported Format | Required Files |
|---|---|---|
| Apache (Linux) | PEM | .crt + .key + ca-bundle.crt |
| Nginx | PEM | .crt (fullchain) + .key |
| IIS (Windows Server) | PFX | .pfx with password |
| Tomcat (Java) | JKS or PKCS#12 | .jks or .p12 |
| HAProxy | PEM | .pem containing key+cert+chain |
| DirectAdmin | PEM | Paste CRT and KEY text into UI |
| cPanel | PEM | Paste certificate text into UI |
| AWS ELB Load Balancer | PEM | Separate .pem for each component |
PEM to PFX (for IIS / Windows)
Bundle the Certificate, Private Key, and CA Chain into a single PFX file:
openssl pkcs12 -export \
-out certificate.pfx \
-inkey privatekey.key \
-in certificate.crt \
-certfile ca-bundle.crt
You will be prompted for a password to protect the PFX file. Always set a strong password.
PFX to PEM (for Apache / Nginx)
Extract Certificate from PFX
openssl pkcs12 -in certificate.pfx -nokeys -out certificate.crt
Extract Private Key from PFX
openssl pkcs12 -in certificate.pfx -nocerts -nodes -out privatekey.key
Extract CA Chain from PFX
openssl pkcs12 -in certificate.pfx -cacerts -nokeys -out ca-bundle.crt
PEM to DER (for Java)
openssl x509 -outform der -in certificate.pem -out certificate.der
DER to PEM
openssl x509 -inform der -in certificate.der -out certificate.pem
PEM to P7B (for IIS)
openssl crl2pkcs7 -nocrl \
-certfile certificate.crt \
-certfile ca-bundle.crt \
-out certificate.p7b
P7B to PEM
openssl pkcs7 -print_certs -in certificate.p7b -out certificate.crt
Create a PEM Bundle (Fullchain) for Nginx and HAProxy
Nginx and HAProxy require a PEM file that combines the Certificate, Intermediate CA, and Root CA into a single file — called a Fullchain Certificate. You must assemble this yourself from the individual files your CA provides.
Create Fullchain for Nginx
# Combine Certificate and CA Bundle into fullchain.pem
cat certificate.crt ca-bundle.crt > fullchain.pem
Reference the fullchain file in your Nginx configuration instead of the standalone certificate:
ssl_certificate /etc/ssl/fullchain.pem;
ssl_certificate_key /etc/ssl/privatekey.key;
Create PEM Bundle for HAProxy
HAProxy requires a single file containing everything, including the Private Key:
# Combine Private Key + Certificate + CA Chain into one bundle
cat privatekey.key certificate.crt ca-bundle.crt > haproxy-bundle.pem
Reference this bundle in your HAProxy configuration file:
bind *:443 ssl crt /etc/ssl/haproxy-bundle.pem
Important: The order inside a bundle file must be correct — Private Key first, then your own Certificate, then the Intermediate CA, then the Root CA. An incorrect order causes TLS handshake failures.
PEM to JKS (for Tomcat / Java)
Java uses Keytool instead of OpenSSL. You must convert via PFX first:
# Step 1: Create PFX first
openssl pkcs12 -export -out certificate.pfx \
-inkey privatekey.key -in certificate.crt \
-certfile ca-bundle.crt
# Step 2: Convert PFX to JKS using keytool
keytool -importkeystore \
-srckeystore certificate.pfx \
-srcstoretype PKCS12 \
-destkeystore keystore.jks \
-deststoretype JKS
Common Errors When Converting SSL Certificate Files
OpenSSL conversion can produce confusing error messages. The table below lists the most common errors with their causes and fixes.
| Error Message | Cause | Fix |
|---|---|---|
unable to load private key |
Key is encrypted or wrong format | Use -nodes to decrypt, or check format with openssl rsa -in key.key -check |
mac verify failure |
Wrong PFX password | Verify the exact password, watch for spaces and special characters |
no certificate matches |
Private Key does not match Certificate | Compare MD5 modulus of both files — they must be identical |
error reading input file |
Wrong file path or filename | Verify the path, use an absolute path, or run the command from the directory containing the files |
certificate is not self signed |
CA Chain is in wrong order | Order certificates from Leaf → Intermediate → Root and verify the chain is complete |
Remove a Passphrase from an Encrypted Private Key
If your Private Key was generated with a passphrase, most web servers require a decrypted version to start without manual password entry:
# Strip the passphrase from an encrypted Private Key
openssl rsa -in privatekey-encrypted.key \
-out privatekey-decrypted.key
The command will prompt for the current passphrase. The output file will be a plain (unencrypted) key ready for use with Apache or Nginx without requiring a password at server startup.
Verify the Certificate Matches the Private Key
After conversion, verify the Private Key matches the Certificate:
# Check Certificate modulus
openssl x509 -noout -modulus -in certificate.crt | openssl md5
# Check Private Key modulus
openssl rsa -noout -modulus -in privatekey.key | openssl md5
# If both MD5 hashes are identical, they match correctly
Need Easy-to-Install SSL Certificates?
AsiaGB provides SSL Certificates from RapidSSL and GeoTrust with a Thai support team to help with installation and format conversion at no extra charge.
View SSL Certificates