Certificates2026-09-29

Convert CRT to PFX: Certificate, Private Key, and Chain

Create a PFX from a CRT with a matching private key and optional CA chain. Check PEM versus DER, verify the key pair, and use OpenSSL or the browser converter.

crtpfxpkcs12opensslcertificates

How to convert a CRT certificate to PFX

A .crt file usually contains a public certificate, not its private key. A deployable PFX (PKCS#12) bundle for a server normally needs the certificate and the private key that matches it. Intermediate CA certificates can be added so the importing system has the chain. Renaming server.crt to server.pfx does not create that bundle.

Input Purpose Required?
server.crt Your issued leaf certificate Yes
server.key The matching private key, often created when the CSR was generated Yes for a server identity PFX
intermediates.pem CA intermediates, in PEM form Optional, but usually useful

The certificate authority generally issues the certificate, not your private key. If the key is lost, request or reissue a certificate for a new key pair; it cannot be recovered from the CRT.

1. Check whether the CRT is PEM or DER

Open the file in a text editor. A PEM certificate starts with -----BEGIN CERTIFICATE-----; DER is binary. The .crt extension alone does not tell you the encoding. You can also test with OpenSSL:

openssl x509 -in server.crt -noout -subject -issuer
# If that cannot read the file, try:
openssl x509 -inform DER -in server.crt -noout -subject -issuer

If the second command succeeds, convert it before using the browser tool:

openssl x509 -inform DER -in server.crt -out server.pem

For a text CRT, server.crt can be used directly as a PEM input. See PEM vs CRT and other certificate formats for the distinction between file names, encodings, and containers.

2. Confirm that the private key matches

The Certificate Key Matcher checks RSA pairs in your browser. For RSA or EC keys on your own machine, compare the public keys derived from each file:

openssl x509 -in server.crt -pubkey -noout > cert-public.pem
openssl pkey -in server.key -pubout > key-public.pem
diff cert-public.pem key-public.pem

diff should produce no output. If your CRT is DER, use server.pem from step 1. Do not upload or publish the private key to troubleshoot a mismatch.

3. Export the PFX

With OpenSSL, use the leaf certificate and matching key. Add -certfile intermediates.pem if your CA supplied intermediate certificates:

openssl pkcs12 -export -in server.crt -inkey server.key \
  -certfile intermediates.pem -out server.pfx

OpenSSL prompts for an export password. Omit -certfile intermediates.pem if you do not have a separate chain file. If the CRT was DER, replace server.crt with server.pem in this command. Keep both the key and resulting PFX in restricted storage.

You can instead use Convert PEM to PFX: upload the PEM certificate, paste the matching PEM key, optionally paste CA certificates and set a password. The conversion runs in your browser. Its current implementation expects a PEM certificate and an RSA private key; use OpenSSL for other key types or encrypted key formats it cannot parse. A blank password may be accepted by the converter, but use a strong one when the target system supports it.

4. Inspect the result

openssl pkcs12 -in server.pfx -info -noout

This confirms that OpenSSL can read the archive. On the destination system, also check that the imported identity includes a private key and the expected certificate chain. OpenSSL's pkcs12 documentation describes the export options and certificate inputs.