How to convert a CRT certificate to PFX
A .crt file usually contains a public certificate, not its private key. A deployable PFX (PKCS#12) bundle for a server normally needs the certificate and the private key that matches it. Intermediate CA certificates can be added so the importing system has the chain. Renaming server.crt to server.pfx does not create that bundle.
| Input | Purpose | Required? |
|---|---|---|
server.crt |
Your issued leaf certificate | Yes |
server.key |
The matching private key, often created when the CSR was generated | Yes for a server identity PFX |
intermediates.pem |
CA intermediates, in PEM form | Optional, but usually useful |
The certificate authority generally issues the certificate, not your private key. If the key is lost, request or reissue a certificate for a new key pair; it cannot be recovered from the CRT.
1. Check whether the CRT is PEM or DER
Open the file in a text editor. A PEM certificate starts with -----BEGIN CERTIFICATE-----; DER is binary. The .crt extension alone does not tell you the encoding. You can also test with OpenSSL:
openssl x509 -in server.crt -noout -subject -issuer
# If that cannot read the file, try:
openssl x509 -inform DER -in server.crt -noout -subject -issuer
If the second command succeeds, convert it before using the browser tool:
openssl x509 -inform DER -in server.crt -out server.pem
For a text CRT, server.crt can be used directly as a PEM input. See PEM vs CRT and other certificate formats for the distinction between file names, encodings, and containers.
2. Confirm that the private key matches
The Certificate Key Matcher checks RSA pairs in your browser. For RSA or EC keys on your own machine, compare the public keys derived from each file:
openssl x509 -in server.crt -pubkey -noout > cert-public.pem
openssl pkey -in server.key -pubout > key-public.pem
diff cert-public.pem key-public.pem
diff should produce no output. If your CRT is DER, use server.pem from step 1. Do not upload or publish the private key to troubleshoot a mismatch.
3. Export the PFX
With OpenSSL, use the leaf certificate and matching key. Add -certfile intermediates.pem if your CA supplied intermediate certificates:
openssl pkcs12 -export -in server.crt -inkey server.key \
-certfile intermediates.pem -out server.pfx
OpenSSL prompts for an export password. Omit -certfile intermediates.pem if you do not have a separate chain file. If the CRT was DER, replace server.crt with server.pem in this command. Keep both the key and resulting PFX in restricted storage.
You can instead use Convert PEM to PFX: upload the PEM certificate, paste the matching PEM key, optionally paste CA certificates and set a password. The conversion runs in your browser. Its current implementation expects a PEM certificate and an RSA private key; use OpenSSL for other key types or encrypted key formats it cannot parse. A blank password may be accepted by the converter, but use a strong one when the target system supports it.
4. Inspect the result
openssl pkcs12 -in server.pfx -info -noout
This confirms that OpenSSL can read the archive. On the destination system, also check that the imported identity includes a private key and the expected certificate chain. OpenSSL's pkcs12 documentation describes the export options and certificate inputs.