Skip to main content
SSL Tool 100% Client-Side

SSL Certificate Converter

Convert between PEM, DER, PFX/P12, P7B, CSR formats — 100% client-side

All operations are 100% client-side. Your private keys never leave your browser.
Input Method
Conversion Type

Conversion result will appear here

Fill in the input panel and click Convert

Frequently Asked Questions

What is the difference between PEM and DER?

PEM (Privacy Enhanced Mail) is a Base64-encoded text format with header/footer lines. DER (Distinguished Encoding Rules) is the raw binary ASN.1 encoding. PEM is human-readable and widely used in Apache/Nginx; DER is used in Java keystores and some Windows applications.

What is a PFX/P12 file?

PFX (Personal Information Exchange) or PKCS#12 (.p12) is an archive format that bundles a certificate with its private key and optionally intermediate certificates, all protected by a password. It is commonly used with IIS and Windows servers.

Is it safe to convert certificates in the browser?

Yes. This tool uses the node-forge library to perform all operations entirely in your browser. No data is transmitted to any server. Your private keys never leave your device.

Why do I need a private key for PFX conversion?

The PFX/PKCS#12 format is designed to bundle a certificate together with its corresponding private key. Without the private key, the PFX file cannot be created.

What is a P7B / PKCS#7 file?

P7B (PKCS#7) is a Base64-encoded container that holds one or more certificates (usually a certificate chain). It does not contain private keys. It is commonly used in Windows and Java environments.

What is a CSR?

A Certificate Signing Request (CSR) is a block of encoded text containing information about your organization and the public key. You submit it to a Certificate Authority (CA) to obtain a signed certificate. CSRs can be in PEM (Base64 text) or DER (binary) format.

Expert guide · SSL Converter

Technical background

Every X.509 certificate (RFC 5280) is ultimately an ASN.1 structure serialized with the Distinguished Encoding Rules. DER is that raw binary form. PEM, standardized for this use in RFC 7468, is simply the DER bytes in Base64 with -----BEGIN label----- and -----END label----- lines, which makes it safe to paste into email or configuration files and allows several objects to be concatenated in one file. The label tells you what is inside: CERTIFICATE, CERTIFICATE REQUEST, PRIVATE KEY (PKCS#8, RFC 5958), RSA PRIVATE KEY (PKCS#1, RFC 8017) or ENCRYPTED PRIVATE KEY. File extensions such as .crt, .cer and .key say nothing reliable about the encoding; a .cer from Windows may be DER or PEM.

PKCS#7, defined in RFC 2315 and generalized as CMS in RFC 5652, is a container. A .p7b file is a degenerate SignedData structure that carries only certificates, never private keys, and is commonly used by Windows and some CAs to ship a chain. PKCS#12 (RFC 7292), with extensions .pfx or .p12, is a password-protected archive that can hold a private key, its certificate and the CA chain together. Its contents are encrypted with a password-based scheme and protected by a MAC; OpenSSL 3 defaults to AES-256-CBC with PBKDF2, while older files use 3DES or RC2-40, which OpenSSL 3 only opens with the -legacy option.

This tool uses node-forge for all of it, so private keys and passwords stay in the browser. A few behaviors are worth knowing. Private key conversions handle RSA keys; ECDSA keys should be converted with openssl pkey. When building a PFX from PEM, the tool packages the leaf certificate and the key; if the target server needs the intermediates inside the PFX, create it with openssl pkcs12 -export and the -certfile option. When extracting from a PFX, the key comes out unencrypted, so treat the result like the original key file.

Most conversions can also be reproduced with OpenSSL, which is useful for scripting: openssl x509 -outform der converts a certificate to DER, openssl crl2pkcs7 -nocrl builds a P7B, openssl pkcs7 -print_certs extracts it, and openssl pkcs12 handles PFX both ways. Re-encoding never changes the cryptographic content: the signature, serial number and validity dates are identical, and the SHA-256 fingerprint of the DER bytes stays the same regardless of the container.

Common errors and how to fix them

Problem OpenSSL 3 says unsupported algorithm RC2-40-CBC when opening an old PFX.
Fix The file uses a legacy cipher disabled by default in OpenSSL 3. Add -legacy to the openssl pkcs12 command, then re-export with modern defaults so other tools can read it.
Problem IIS imports the PFX but browsers report a missing intermediate.
Fix The PFX contained only the leaf certificate. Rebuild it with openssl pkcs12 -export ... -certfile chain.pem, or import the intermediate separately into the Intermediate Certification Authorities store.
Problem Nginx fails with PEM_read_bio: no start line.
Fix Nginx was given a DER or PFX file. Convert it to PEM first and confirm the file starts with -----BEGIN CERTIFICATE----- or -----BEGIN PRIVATE KEY-----.
Problem PEM to PFX is impossible because the key is not available.
Fix PKCS#12 must contain the private key that matches the certificate. Locate the key on the server where the CSR was generated; if it is lost, generate a new CSR and request a reissue.
Problem A legacy application rejects a key that begins with BEGIN PRIVATE KEY.
Fix Convert PKCS#8 to PKCS#1 with the PEM to Traditional RSA option, or run openssl rsa -in key.pem -traditional -out key.rsa.pem with OpenSSL 3.

Do it from the command line

macOS

# PEM certificate to DER and back
openssl x509 -in cert.pem -outform der -out cert.der
openssl x509 -in cert.der -inform der -out cert.pem
# Build a PFX that includes the intermediate chain
openssl pkcs12 -export -inkey key.pem -in cert.pem -certfile chain.pem -out site.pfx

Windows

# DER to Base64 PEM with certutil
certutil -encode cert.der cert.pem
# Inspect a PFX (prompts for password)
certutil -dump site.pfx
# Export a cert with key from the store as PFX (PowerShell)
Export-PfxCertificate -Cert Cert:\LocalMachine\My\<THUMBPRINT> -FilePath site.pfx -Password (Read-Host -AsSecureString)

Linux

# PEM chain to P7B and P7B back to PEM
openssl crl2pkcs7 -nocrl -certfile cert.pem -certfile chain.pem -out bundle.p7b
openssl pkcs7 -in bundle.p7b -print_certs -out bundle.pem
# Split a PFX into key and certificates (add -legacy for old RC2/3DES files)
openssl pkcs12 -in site.pfx -nocerts -nodes -out key.pem
openssl pkcs12 -in site.pfx -nokeys -out fullchain.pem

More questions about SSL Converter

What is the difference between .crt, .cer, .pem and .der?

Only two encodings exist underneath: PEM, which is Base64 text with BEGIN and END lines, and DER, which is raw binary. The extensions .crt and .cer are used for both, so open the file in a text editor: readable BEGIN CERTIFICATE lines mean PEM, unreadable bytes mean DER. The certificate content is identical either way.

Is it safe to convert a PFX with my private key online?

Only if the conversion happens locally. This converter runs node-forge in your browser, and neither the file nor the password is uploaded; you can verify there are no network requests in developer tools. Avoid any service that requires uploading a PFX to a server, because that hands over your private key.

Can a P7B file contain my private key?

No. A PKCS#7 .p7b bundle carries certificates only, typically your leaf and the intermediates. If you need a single file with the key included, use PKCS#12 (.pfx or .p12), which is encrypted with a password and supported by Windows, Java and most load balancers.

Why does my converted PFX not work on older Windows or Java versions?

Modern OpenSSL 3 protects PKCS#12 files with AES-256 and PBKDF2, which Windows Server 2016 and earlier or old Java releases cannot read. Re-export with openssl pkcs12 -export -legacy, or with -keypbe and -certpbe set to PBE-SHA1-3DES and -macalg sha1 for maximum compatibility.

Does converting a certificate change its fingerprint?

No. The fingerprint is a hash of the DER-encoded certificate, and PEM is just Base64 of those same bytes. Wrapping the certificate in P7B or PFX also leaves it unchanged inside. If a fingerprint differs after conversion, you are looking at a different certificate, often an intermediate exported by mistake.

100-Day Max Lifespan
155d 5h 19m 9s
PQC Migration Target
1178d 5h 19m 9s