Key facts
- Can be PEM text (-----BEGIN CERTIFICATE-----) or binary DER; the extension does not say which.
- Contains the subject, issuer, validity dates, public key, Subject Alternative Names (hostnames) and CA signature, but no private key.
- MIME types include application/pkix-cert and application/x-x509-ca-cert.
- Typically 1-2 KB per certificate; .cer is an equivalent extension common on Windows.
How to open a .crt file
Double-click it to open the Certificate dialog showing General, Details and Certification Path tabs. Install it from there or via certlm.msc only if you trust the issuer.
Select it and press Space for Quick Look, or double-click to add it to Keychain Access, where you can read all fields.
Run openssl x509 -in site.crt -noout -text (add -inform der for binary files). System CA certificates go into /usr/local/share/ca-certificates/ followed by sudo update-ca-certificates.
Common problems and fixes
- Browser shows 'certificate not trusted' or incomplete chain
- The server is not sending the intermediate certificate(s). Concatenate your certificate followed by the CA bundle into one file and point Nginx's ssl_certificate (or Apache's SSLCertificateFile) to it.
- NET::ERR_CERT_COMMON_NAME_INVALID
- The hostname is not in the certificate's Subject Alternative Names. Check them with openssl x509 -noout -ext subjectAltName and reissue the certificate covering the www and non-www names you serve.
- Certificate expired
- Check the date with openssl x509 -noout -enddate, renew it with your CA or ACME client (certbot renew), install the new file and reload the web server.
- Server rejects the .crt file format
- It is probably DER while the server expects PEM. Convert it with openssl x509 -inform der -in site.crt -out site.pem.
Often converted to or from: PEM, DER/CER, PFX/P12, P7B