PEM vs CRT: what is the difference?
PEM describes a text encoding with -----BEGIN ...----- and -----END ...----- boundaries around Base64 data. CRT is a filename extension often used for a certificate. They are not competing encodings: a file named server.crt may already be PEM. Another .crt or .cer file may contain binary DER instead. Inspect the contents before converting or renaming anything.
-----BEGIN CERTIFICATE-----
...Base64 certificate data...
-----END CERTIFICATE-----
The block above represents an X.509 certificate in PEM form. A PEM file can also contain a private key, a certificate signing request, or several certificate blocks, depending on its labels and contents. The extension alone cannot tell you which.
Extension, encoding, and container are different things
| Name | Usually means | Can contain a private key? | Quick identification |
|---|---|---|---|
.pem |
Text PEM armor around an object | Yes, if it has a private-key block | Read the BEGIN label |
.crt / .cer |
Certificate filename convention | Normally no | Check for BEGIN CERTIFICATE; otherwise try DER parsing |
.der |
Binary ASN.1 DER encoding, often an X.509 certificate | Possible for key objects, depending on the file | Binary data; inspect with OpenSSL |
.pfx / .p12 |
PKCS#12 bundle | Yes; may include a key, certificate, and CA certificates | Use openssl pkcs12 -info -noout |
.p7b / .p7c |
PKCS#7/CMS certificate bundle | Typically contains certificates, not a private key | Use openssl pkcs7 -print_certs for supported input |
.key |
Private-key filename convention | Yes | Check the PEM label or key format |
.csr |
Certificate signing request | No private key; includes a public key | BEGIN CERTIFICATE REQUEST |
Treat these as conventions, not guarantees. A renamed file does not change its internal encoding. The important questions are which object is inside, how it is encoded, and what the receiving software expects.
How to identify a CRT or CER file
First, open it as text. If it has a BEGIN CERTIFICATE header, it is PEM-encoded. Confirm the certificate fields:
openssl x509 -in server.crt -noout -subject -issuer -dates
If it looks binary or that command fails, test DER input:
openssl x509 -inform DER -in server.crt -noout -subject -issuer -dates
If neither works, verify that the file really contains an X.509 certificate. It may instead be a certificate bundle, CSR, key, or another format. The PEM Decoder helps inspect text PEM blocks; the Certificate Decoder shows certificate fields from supported input. Do not paste a private key into a certificate-only inspection workflow.
Conversion recipes
DER certificate to PEM certificate:
openssl x509 -inform DER -in server.der -out server.pem
PEM certificate to DER certificate:
openssl x509 -in server.pem -outform DER -out server.der
PEM certificate plus matching key to PFX:
openssl pkcs12 -export -in server.crt -inkey server.key \
-certfile intermediates.pem -out server.pfx
Omit -certfile when there is no separate intermediate file. A CRT containing a DER certificate needs conversion to PEM first for that example. The PFX requires the matching private key; you cannot derive it from the public certificate. See the step-by-step CRT to PFX guide, or use Convert PEM to PFX for supported PEM/RSA inputs in your browser.
Inspect a PFX without exporting its key:
openssl pkcs12 -in server.pfx -info -noout
Read certificates from a PEM-encoded PKCS#7 file:
openssl pkcs7 -print_certs -in chain.p7b -out chain.pem
If that P7B is binary DER, add -inform DER. For command options and compatibility details, see the OpenSSL x509 and pkcs12 manuals.
Which file should go on a web server?
Many TLS servers use a PEM leaf certificate followed by intermediate certificates as a full chain, plus a separate private-key file. The trusted root normally comes from the client's trust store; servers generally do not need to send it. A .pfx is useful when a platform imports a certificate and private key as one identity bundle. Always follow the target product's instructions for file ordering and key permissions.
For a broken trust path or a missing intermediate, follow how to verify a certificate chain with OpenSSL. Format conversion alone cannot repair an expired certificate, mismatched key, or untrusted issuer.