Skip to main content

SSL Tools

Certificate Key Matcher

Verify that your SSL certificate and private key are a matching pair — 100% client-side

Your private key never leaves your browser. All verification is 100% client-side.

Why Certificate-Key Matching Matters

SSL/TLS certificates and private keys are generated as mathematically linked pairs. When deploying HTTPS on a web server, you must provide a certificate and its corresponding private key. If they do not match, the server will fail to start TLS handshakes and visitors will see connection errors.

Mismatches commonly occur when certificates are renewed without generating a new key, when multiple certificates exist for the same domain, or when files are accidentally mixed up during server migration. System administrators managing many domains are especially prone to this issue.

The modulus comparison method is the standard way to verify a match. Both the certificate's public key and the private key contain the same RSA modulus (a large prime product). By extracting and hashing the modulus from each, we can quickly determine if they belong to the same key pair. This tool computes the MD5 hash of each modulus entirely in your browser using the node-forge library — your private key is never transmitted anywhere.

Frequently Asked Questions

How does modulus comparison work?

An RSA key pair shares a common modulus — the product of two large primes. The certificate contains the public key (with the modulus), and the private key also contains this modulus. If both modulus values are identical, the certificate and key are a matching pair.

Is it safe to paste my private key here?

Yes. This tool runs entirely in your browser using the node-forge JavaScript library. Your private key is never sent to any server. You can verify this by checking your browser's Network tab — no requests are made when you click Verify.

What formats are supported?

This tool supports PEM-encoded RSA certificates and private keys. PEM files are Base64-encoded text starting with -----BEGIN CERTIFICATE----- or -----BEGIN RSA PRIVATE KEY----- / -----BEGIN PRIVATE KEY-----. If you have DER or PFX files, convert them to PEM first using our SSL Converter tool.

What if my certificate and key don't match?

If they don't match, you likely have the wrong key for your certificate. You'll need to either find the correct private key that was used to generate the CSR for this certificate, or generate a new CSR with your existing key and request a new certificate from your CA.

Expert guide · Certificate Key Matcher

What it does

The Certificate Key Matcher confirms whether an X.509 certificate and an RSA private key belong to the same key pair. Using node-forge in your browser, it extracts the RSA modulus from the certificate's public key and from the private key, compares the full values, and displays a match or mismatch verdict alongside an MD5 digest and the first 40 hex digits of each modulus. The private key is never transmitted; clicking Verify triggers no network request.

Why it matters

  • Prevent failed reloads: Nginx refuses to start with key values mismatch, which can take a site offline if the bad pair is deployed during a renewal window.
  • Messy key directories: Servers that have been renewed many times accumulate files like server.key, server-new.key and server-2025.key; matching tells you which one to keep.
  • Reissue confusion: After a CA reissue triggered by a new CSR, the old key no longer fits the new certificate, a frequent cause of failed deployments.
  • Load balancer and CDN uploads: Cloud consoles often reject a mismatched pair with a vague error; checking first saves trial and error.
  • Incident response: When a key may be compromised, you need to know exactly which certificates are tied to it before revoking.

How to read the results

  • Match verdict: Green means the certificate's public modulus is identical to the private key's modulus, so the pair will load together; red means they come from different key pairs.
  • Certificate MD5 and Key MD5: Short fingerprints for visual comparison. They are computed over the lowercase hex modulus string, so they will not equal the output of openssl x509 -modulus | openssl md5, which hashes a different text.
  • Modulus preview: The first 40 hex characters of each modulus; identical prefixes with a mismatch verdict are effectively impossible, so a difference here confirms the result at a glance.
  • Invalid certificate error: The input is not a PEM certificate; a CSR, a DER file or a chain with a broken header triggers this.
  • Invalid key error: The key is encrypted (BEGIN ENCRYPTED PRIVATE KEY), is an EC key, or is not PEM. Decrypt or convert it first; this tool compares RSA keys only.

Technical background

In RSA, the public key is the pair (n, e), where n is the modulus, the product of two secret primes, and e is almost always 65537. The private key contains the same n plus the private exponent and the primes. A certificate embeds only the public key in its SubjectPublicKeyInfo field (RFC 5280), so if a certificate and a private key share the same modulus, they are two halves of one key pair. With moduli of 2048 bits or more, an accidental collision between unrelated keys is not a realistic possibility, which is why a modulus comparison is a reliable check.

The classic command-line recipe hashes the modulus printed by OpenSSL: openssl x509 -noout -modulus -in cert.pem | openssl md5 and openssl rsa -noout -modulus -in key.pem | openssl md5. MD5 is acceptable here because the digest is only a short visual comparison of public data, not a security control. The more general method, which also works for ECDSA and Ed25519, compares the whole public key: openssl x509 -noout -pubkey -in cert.pem | openssl sha256 versus openssl pkey -in key.pem -pubout | openssl sha256. The same extraction applied to a CSR (openssl req -noout -pubkey) shows which request a key belongs to.

This page performs the RSA modulus comparison entirely client-side with node-forge. The verdict is based on comparing the full modulus strings, not just the displayed MD5 values, and the MD5 shown is computed over forge's lowercase hexadecimal representation. That representation differs from OpenSSL's Modulus=ABCD... output line, so use the CLI pair of commands among themselves and this tool's hashes among themselves, but do not compare across the two. Encrypted PKCS#8 keys must be decrypted first, and ECDSA pairs should be checked with the SHA-256 public-key method above.

Servers detect a mismatch at load time: Nginx with OpenSSL 3 logs SSL_CTX_use_PrivateKey failed (key values mismatch), Apache reports AH02565, and Windows shows a certificate without You have a private key that corresponds to this certificate. Because certificate lifetimes are falling under CA/B Forum ballot SC-081 (200 days from March 2026, 47 days by 2029), key and certificate swaps happen far more often, and an automated pubkey comparison in your deployment pipeline is a cheap guard against outages.

Common errors and how to fix them

Problem Nginx: SSL_CTX_use_PrivateKey failed (key values mismatch).
Fix ssl_certificate_key points at a key from a different CSR. Search the server for the right key by comparing public-key hashes with every *.key file, or generate a new CSR and request a reissue.
Problem Apache AH02565 Certificate and private key do not match after renewal.
Fix The renewal used a new CSR and key, but SSLCertificateKeyFile still references the old one. Update the path to the new key and run apachectl configtest before reloading.
Problem The tool reports Invalid key for a key that works on the server.
Fix The key is passphrase-protected or EC. Decrypt it with openssl pkey -in key.pem -out key.plain.pem (in a secure location) or use the SHA-256 public-key commands, which handle EC keys.
Problem My MD5 from OpenSSL differs from the one shown here even though the verdict is Match.
Fix Expected: OpenSSL hashes the text Modulus=ABCD... with uppercase hex and a newline, while this tool hashes forge's lowercase hex. Compare like with like; the verdict uses the full modulus.
Problem Windows certificate shows no private key after importing the .cer issued by the CA.
Fix The key lives in the store where the CSR was created. Import the .cer on that same machine and run certutil -repairstore my followed by the serial number to bind it, then export a PFX if needed elsewhere.

Do it from the command line

macOS

# Compare public-key hashes (works for RSA and ECDSA)
openssl x509 -in cert.pem -noout -pubkey | openssl sha256
openssl pkey -in key.pem -pubout | openssl sha256
# Which CSR does this key belong to?
openssl req -in request.csr -noout -pubkey | openssl sha256

Windows

# Classic RSA modulus check with OpenSSL (Git for Windows)
openssl x509 -noout -modulus -in cert.pem | openssl md5
openssl rsa -noout -modulus -in key.pem | openssl md5
# Re-associate a store certificate with its private key
certutil -repairstore my <SERIAL_NUMBER>

Linux

# One-liner: identical hashes mean the pair matches
diff <(openssl x509 -in cert.pem -noout -pubkey) <(openssl pkey -in key.pem -pubout) && echo MATCH
# Validate the Nginx config before reloading
sudo nginx -t

More questions about Certificate Key Matcher

How do I check if a private key matches a certificate?

Compare the public key embedded in the certificate with the public key derived from the private key. On the command line, hash the output of openssl x509 -noout -pubkey and openssl pkey -pubout with SHA-256; identical hashes mean a match. For RSA pairs, this page does the equivalent modulus comparison in your browser.

Is it safe to paste my private key into this tool?

The comparison runs locally with node-forge and no request is made when you click Verify, which you can confirm in the browser Network tab. Still, treat any private key as highly sensitive: use the tool on a trusted machine, clear the field afterwards, and prefer the OpenSSL commands on the server itself for production keys.

Why is MD5 used if MD5 is broken?

MD5 is broken for collision resistance, meaning an attacker can craft two different inputs with the same digest. Here it only produces a short label for public modulus data so humans can compare values; the actual verdict compares the full modulus. For a stronger habit, the SHA-256 public-key method shown in the CLI section is preferable.

Can I match an ECDSA certificate and key here?

No, this tool reads RSA moduli only. For ECDSA or Ed25519 pairs run openssl x509 -in cert.pem -noout -pubkey | openssl sha256 and openssl pkey -in key.pem -pubout | openssl sha256; matching hashes mean the key belongs to the certificate.

Can I tell which CSR a certificate was issued from?

Yes. A certificate, its CSR and its private key all share the same public key. Run openssl req -in request.csr -noout -pubkey | openssl sha256 and compare it with the certificate's public-key hash. This is useful when several CSRs were generated during a renewal and you need to know which key to deploy.

100-Day Max Lifespan
155d 5h 17m 58s
PQC Migration Target
1178d 5h 17m 58s