Certificates2026-02-22

PEM vs CRT, DER, and PFX: Certificate Formats Explained

Learn why PEM and CRT are not opposites, how to identify text or binary certificates, and when to use DER, PFX/P12, or PKCS#7.

ssltlscertificatespemcrtderpfx

PEM vs CRT: what is the difference?

PEM describes a text encoding with -----BEGIN ...----- and -----END ...----- boundaries around Base64 data. CRT is a filename extension often used for a certificate. They are not competing encodings: a file named server.crt may already be PEM. Another .crt or .cer file may contain binary DER instead. Inspect the contents before converting or renaming anything.

-----BEGIN CERTIFICATE-----
...Base64 certificate data...
-----END CERTIFICATE-----

The block above represents an X.509 certificate in PEM form. A PEM file can also contain a private key, a certificate signing request, or several certificate blocks, depending on its labels and contents. The extension alone cannot tell you which.

Extension, encoding, and container are different things

Name Usually means Can contain a private key? Quick identification
.pem Text PEM armor around an object Yes, if it has a private-key block Read the BEGIN label
.crt / .cer Certificate filename convention Normally no Check for BEGIN CERTIFICATE; otherwise try DER parsing
.der Binary ASN.1 DER encoding, often an X.509 certificate Possible for key objects, depending on the file Binary data; inspect with OpenSSL
.pfx / .p12 PKCS#12 bundle Yes; may include a key, certificate, and CA certificates Use openssl pkcs12 -info -noout
.p7b / .p7c PKCS#7/CMS certificate bundle Typically contains certificates, not a private key Use openssl pkcs7 -print_certs for supported input
.key Private-key filename convention Yes Check the PEM label or key format
.csr Certificate signing request No private key; includes a public key BEGIN CERTIFICATE REQUEST

Treat these as conventions, not guarantees. A renamed file does not change its internal encoding. The important questions are which object is inside, how it is encoded, and what the receiving software expects.

How to identify a CRT or CER file

First, open it as text. If it has a BEGIN CERTIFICATE header, it is PEM-encoded. Confirm the certificate fields:

openssl x509 -in server.crt -noout -subject -issuer -dates

If it looks binary or that command fails, test DER input:

openssl x509 -inform DER -in server.crt -noout -subject -issuer -dates

If neither works, verify that the file really contains an X.509 certificate. It may instead be a certificate bundle, CSR, key, or another format. The PEM Decoder helps inspect text PEM blocks; the Certificate Decoder shows certificate fields from supported input. Do not paste a private key into a certificate-only inspection workflow.

Conversion recipes

DER certificate to PEM certificate:

openssl x509 -inform DER -in server.der -out server.pem

PEM certificate to DER certificate:

openssl x509 -in server.pem -outform DER -out server.der

PEM certificate plus matching key to PFX:

openssl pkcs12 -export -in server.crt -inkey server.key \
  -certfile intermediates.pem -out server.pfx

Omit -certfile when there is no separate intermediate file. A CRT containing a DER certificate needs conversion to PEM first for that example. The PFX requires the matching private key; you cannot derive it from the public certificate. See the step-by-step CRT to PFX guide, or use Convert PEM to PFX for supported PEM/RSA inputs in your browser.

Inspect a PFX without exporting its key:

openssl pkcs12 -in server.pfx -info -noout

Read certificates from a PEM-encoded PKCS#7 file:

openssl pkcs7 -print_certs -in chain.p7b -out chain.pem

If that P7B is binary DER, add -inform DER. For command options and compatibility details, see the OpenSSL x509 and pkcs12 manuals.

Which file should go on a web server?

Many TLS servers use a PEM leaf certificate followed by intermediate certificates as a full chain, plus a separate private-key file. The trusted root normally comes from the client's trust store; servers generally do not need to send it. A .pfx is useful when a platform imports a certificate and private key as one identity bundle. Always follow the target product's instructions for file ordering and key permissions.

For a broken trust path or a missing intermediate, follow how to verify a certificate chain with OpenSSL. Format conversion alone cannot repair an expired certificate, mismatched key, or untrusted issuer.