
从证书颁发机构(CA)接收 SSL 证书后,您收到的文件格式可能与您的服务器或应用程序所需的格式不匹配。Apache 需要 PEM 格式,但您有 PFX 格式,或者您的 Java 应用程序服务器需要 JKS 格式。本指南涵盖了在所有常见格式之间转换 SSL 证书文件所需的每个 OpenSSL 命令。
常见 SSL 证书文件格式
在转换之前,了解每种格式之间的区别:
- PEM (.pem, .crt, .cer, .key) — Base64 编码格式,使用最广泛。适用于 Apache、Nginx、HAProxy。以
-----BEGIN CERTIFICATE-----开头 - DER (.der, .cer) — Java 和 Windows 使用的二进制格式
- PFX/PKCS#12 (.pfx, .p12) — 包含证书 + 私钥 + 链的包,全部在一个文件中。与 IIS、Windows Server 一起使用
- JKS (.jks) — Tomcat 和 Java 应用程序服务器使用的 Java 密钥库
- P7B/PKCS#7 (.p7b, .p7c) — 包含多个证书,不包含私钥。与 IIS 一起使用
提示:首先使用 openssl x509 -in cert.crt -text -noout 检查当前格式。如果它成功显示文本,则为 PEM 格式。否则,请尝试 DER 命令。
SSL 文件格式和网络服务器兼容性
在决定转换路径之前,使用此快速参考表来确定目标平台需要的格式。
| 网络服务器 / 平台 | 支持的格式 | 所需文件 |
|---|---|---|
| Apache (Linux) | PEM | .crt + .key + ca-bundle.crt |
| Nginx | PEM | .crt (fullchain) + .key |
| IIS (Windows Server) | PFX | .pfx with password |
| Tomcat (Java) | JKS or PKCS#12 | .jks or .p12 |
| HAProxy | PEM | .pem containing key+cert+chain |
| DirectAdmin | PEM | Paste CRT and KEY text into UI |
| cPanel | PEM | Paste certificate text into UI |
| AWS ELB Load Balancer | PEM | Separate .pem for each component |
PEM 转 PFX(用于 IIS / Windows)
将证书、私钥和 CA 链捆绑到单个 PFX 文件中:
openssl pkcs12 -export \
-out certificate.pfx \
-inkey privatekey.key \
-in certificate.crt \
-certfile ca-bundle.crt
系统会提示您输入密码来保护 PFX 文件。始终设置强密码。
PFX 转 PEM(用于 Apache / Nginx)
从 PFX 提取证书
openssl pkcs12 -in certificate.pfx -nokeys -out certificate.crt
从 PFX 提取私钥
openssl pkcs12 -in certificate.pfx -nocerts -nodes -out privatekey.key
从 PFX 提取 CA 链
openssl pkcs12 -in certificate.pfx -cacerts -nokeys -out ca-bundle.crt
PEM 转 DER(用于 Java)
openssl x509 -outform der -in certificate.pem -out certificate.der
DER 转 PEM
openssl x509 -inform der -in certificate.der -out certificate.pem
PEM 转 P7B(用于 IIS)
openssl crl2pkcs7 -nocrl \
-certfile certificate.crt \
-certfile ca-bundle.crt \
-out certificate.p7b
P7B 转 PEM
openssl pkcs7 -print_certs -in certificate.p7b -out certificate.crt
为 Nginx 和 HAProxy 创建 PEM 包(全链)
Nginx 和 HAProxy 需要一个 PEM 文件,将证书、中间 CA 和根 CA 组合到一个文件中 — 称为全链证书。您必须从 CA 提供的各个文件中自己组装。
为 Nginx 创建全链
# 将证书和 CA 包组合到 fullchain.pem 中
cat certificate.crt ca-bundle.crt > fullchain.pem
在您的 Nginx 配置中引用全链文件,而不是独立证书:
ssl_certificate /etc/ssl/fullchain.pem;
ssl_certificate_key /etc/ssl/privatekey.key;
为 HAProxy 创建 PEM 包
HAProxy 需要一个包含所有内容(包括私钥)的单个文件:
# 将私钥 + 证书 + CA 链组合到一个包中
cat privatekey.key certificate.crt ca-bundle.crt > haproxy-bundle.pem
在您的 HAProxy 配置文件中引用此包:
bind *:443 ssl crt /etc/ssl/haproxy-bundle.pem
重要:包文件内的顺序必须正确 — 首先是私钥,然后是您自己的证书,然后是中间 CA,最后是根 CA。顺序不正确会导致 TLS 握手失败。
PEM 转 JKS(用于 Tomcat / Java)
Java 使用 Keytool 而不是 OpenSSL。您必须先通过 PFX 进行转换:
# 第 1 步:首先创建 PFX
openssl pkcs12 -export -out certificate.pfx \
-inkey privatekey.key -in certificate.crt \
-certfile ca-bundle.crt
# 第 2 步:使用 keytool 将 PFX 转换为 JKS
keytool -importkeystore \
-srckeystore certificate.pfx \
-srcstoretype PKCS12 \
-destkeystore keystore.jks \
-deststoretype JKS
转换 SSL 证书文件时的常见错误
OpenSSL 转换会产生令人困惑的错误消息。下表列出了最常见的错误及其原因和解决方案。
| 错误消息 | 原因 | 修复 |
|---|---|---|
unable to load private key |
密钥已加密或格式错误 | 使用 -nodes 解密,或使用 openssl rsa -in key.key -check 检查格式 |
mac verify failure |
PFX 密码错误 | 验证确切的密码,注意空格和特殊字符 |
no certificate matches |
私钥与证书不匹配 | 比较两个文件的 MD5 模数 — 它们必须相同 |
error reading input file |
文件路径或文件名错误 | 验证路径,使用绝对路径,或从包含文件的目录运行命令 |
certificate is not self signed |
CA 链顺序错误 | 从叶 → 中间 → 根排序证书,并验证链是否完整 |
从加密的私钥中移除密码
如果您的私钥是用密码生成的,大多数网络服务器需要一个解密的版本来启动,而无需手动输入密码:
# 从加密的私钥中去除密码
openssl rsa -in privatekey-encrypted.key \
-out privatekey-decrypted.key
该命令将提示输入当前密码。输出文件将是一个纯文本(未加密)密钥,可用于 Apache 或 Nginx,而无需在服务器启动时输入密码。
验证证书与私钥匹配
转换后,验证私钥与证书匹配:
# 检查证书模数
openssl x509 -noout -modulus -in certificate.crt | openssl md5
# 检查私钥模数
openssl rsa -noout -modulus -in privatekey.key | openssl md5
# 如果两个 MD5 哈希相同,则它们匹配正确