Certificate Key Matcher — Verify SSL Certificate & Private Key Match
Check if an SSL certificate and private key are a matching pair by comparing their RSA modulus — 100% client-side.
Jump to tool ↓Frequently Asked Questions
Why Verify Certificate and Key Pairing?
When installing an SSL/TLS certificate, one of the most common configuration errors is mismatched certificate and private key files. Nginx will report SSL_CTX_use_PrivateKey_file failed, Apache returns AH02217: ssl_util_ppopen, and HAProxy simply refuses to start.
This mismatch happens because SSL certificates and their private keys are mathematically linked. The certificate contains the public key. The private key is the only key that corresponds to that public key. Using any other private key — even a valid RSA key of the same size — will not work.
For RSA keys, the link can be verified by comparing the modulus — the large composite number (product of two primes) that defines the RSA key pair. The public key in the certificate and the private key must share the same modulus value. If they do, they are a matching pair.
This is exactly what openssl x509 -noout -modulus and openssl rsa -noout -modulusdo, and what this tool replicates in-browser using node-forge. No data leaves your machine.
Standards & References
Built and maintained by DevDecode. This tool processes your input in your browser; it is not uploaded for processing. Found an issue? Let us know.
Related Tools
Related Guides
Convert CRT to PFX: Certificate, Private Key, and Chain
Create a PFX from a CRT with a matching private key and optional CA chain. Check PEM versus DER, verify the key pair, and use OpenSSL or the browser converter.
CertificatesWhat Happens When an SSL Certificate Expires (and How to Check)
When an SSL certificate expires, browsers block the site with a security warning. Learn the exact impact, how to check a certificate's expiration date, and how to prevent downtime.
CertificatesHow to Convert PFX to PEM (OpenSSL + Online)
Convert a .pfx/.p12 file to PEM with OpenSSL or in your browser. Split the cert, key, and chain, handle the password, and fix the legacy-algorithm error.
CertificatesHow to Create a Self-Signed Certificate with OpenSSL
Generate a self-signed SSL certificate with OpenSSL in one command, add Subject Alternative Names for modern browsers, and know when to use one (and when not to).