Ffile2fix
Sign in Get started

What is a .crt file?

A .crt file contains an X.509 digital certificate, most often the SSL/TLS certificate for a website or an intermediate/root CA certificate. You receive it from a certificate authority and install it on a web server together with its private key.

Key facts

  • Can be PEM text (-----BEGIN CERTIFICATE-----) or binary DER; the extension does not say which.
  • Contains the subject, issuer, validity dates, public key, Subject Alternative Names (hostnames) and CA signature, but no private key.
  • MIME types include application/pkix-cert and application/x-x509-ca-cert.
  • Typically 1-2 KB per certificate; .cer is an equivalent extension common on Windows.

How to open a .crt file

Windows

Double-click it to open the Certificate dialog showing General, Details and Certification Path tabs. Install it from there or via certlm.msc only if you trust the issuer.

macOS

Select it and press Space for Quick Look, or double-click to add it to Keychain Access, where you can read all fields.

Linux

Run openssl x509 -in site.crt -noout -text (add -inform der for binary files). System CA certificates go into /usr/local/share/ca-certificates/ followed by sudo update-ca-certificates.

Common problems and fixes

Browser shows 'certificate not trusted' or incomplete chain
The server is not sending the intermediate certificate(s). Concatenate your certificate followed by the CA bundle into one file and point Nginx's ssl_certificate (or Apache's SSLCertificateFile) to it.
NET::ERR_CERT_COMMON_NAME_INVALID
The hostname is not in the certificate's Subject Alternative Names. Check them with openssl x509 -noout -ext subjectAltName and reissue the certificate covering the www and non-www names you serve.
Certificate expired
Check the date with openssl x509 -noout -enddate, renew it with your CA or ACME client (certbot renew), install the new file and reload the web server.
Server rejects the .crt file format
It is probably DER while the server expects PEM. Convert it with openssl x509 -inform der -in site.crt -out site.pem.

Often converted to or from: PEM, DER/CER, PFX/P12, P7B

Frequently asked questions

Does a .crt file contain the private key?

No. A certificate only contains the public key. The matching private key was generated with your CSR and is stored separately, usually as a .key file.

What is the difference between .crt and .cer?

They are interchangeable names for certificate files. Either can be PEM or DER; Windows tends to use .cer and Linux servers .crt.

Is it safe to share a .crt file?

Yes. Certificates are public and every visitor's browser receives yours. Only the private key must be kept secret.

See all file types β†’ Β· Browse error fixes β†’