Key facts
- Usually PEM text starting with -----BEGIN PRIVATE KEY----- (PKCS#8), -----BEGIN RSA PRIVATE KEY----- (PKCS#1) or -----BEGIN EC PRIVATE KEY-----.
- -----BEGIN ENCRYPTED PRIVATE KEY----- means it is protected by a passphrase.
- RSA 2048-bit keys are about 1.7 KB; ECDSA keys are a few hundred bytes.
- Created by openssl req/genpkey, certbot, hosting control panels or Windows when exporting from a PFX.
How to open a .key file
Open it in Notepad only to check the BEGIN line, then close it. Inspect it with OpenSSL (bundled with Git for Windows): openssl pkey -in server.key -noout -text.
If it is a Keynote presentation, open it in Keynote. For a private key, use Terminal: openssl pkey -in server.key -noout to verify it loads.
Verify it with openssl pkey -in server.key -noout, inspect details with -text, and lock it down with chmod 600 server.key and an owner of root or the service user.
Common problems and fixes
- SSL error: key values mismatch / private key does not match certificate
- Compare openssl pkey -in server.key -pubout with openssl x509 -in server.crt -noout -pubkey; the output must be identical. If not, locate the key used for that CSR or reissue the certificate with a new key.
- Server prompts for a passphrase on restart
- The key is encrypted. Create an unencrypted copy with openssl pkey -in encrypted.key -out server.key, then protect it with chmod 600.
- 'unable to load private key' or 'bad decrypt'
- The passphrase is wrong, the file is DER instead of PEM, or text was altered while copying. Re-export it, or convert DER with openssl pkey -inform der -in key.der -out server.key.
- Lost the private key
- A private key cannot be recovered from the certificate. Generate a new key and CSR and ask your CA to reissue the certificate (usually free).
Often converted to or from: PEM, DER, PFX/P12 (with certificate), PKCS#1 / PKCS#8