Ffile2fix
Sign in Get started

What is a .key file?

On servers, a .key file usually holds the private key that pairs with an SSL/TLS certificate, created when you generated the CSR. It must stay secret: anyone with it can impersonate your site. On a Mac, a .key file may instead be an Apple Keynote presentation.

Key facts

  • Usually PEM text starting with -----BEGIN PRIVATE KEY----- (PKCS#8), -----BEGIN RSA PRIVATE KEY----- (PKCS#1) or -----BEGIN EC PRIVATE KEY-----.
  • -----BEGIN ENCRYPTED PRIVATE KEY----- means it is protected by a passphrase.
  • RSA 2048-bit keys are about 1.7 KB; ECDSA keys are a few hundred bytes.
  • Created by openssl req/genpkey, certbot, hosting control panels or Windows when exporting from a PFX.

How to open a .key file

Windows

Open it in Notepad only to check the BEGIN line, then close it. Inspect it with OpenSSL (bundled with Git for Windows): openssl pkey -in server.key -noout -text.

macOS

If it is a Keynote presentation, open it in Keynote. For a private key, use Terminal: openssl pkey -in server.key -noout to verify it loads.

Linux

Verify it with openssl pkey -in server.key -noout, inspect details with -text, and lock it down with chmod 600 server.key and an owner of root or the service user.

Common problems and fixes

SSL error: key values mismatch / private key does not match certificate
Compare openssl pkey -in server.key -pubout with openssl x509 -in server.crt -noout -pubkey; the output must be identical. If not, locate the key used for that CSR or reissue the certificate with a new key.
Server prompts for a passphrase on restart
The key is encrypted. Create an unencrypted copy with openssl pkey -in encrypted.key -out server.key, then protect it with chmod 600.
'unable to load private key' or 'bad decrypt'
The passphrase is wrong, the file is DER instead of PEM, or text was altered while copying. Re-export it, or convert DER with openssl pkey -inform der -in key.der -out server.key.
Lost the private key
A private key cannot be recovered from the certificate. Generate a new key and CSR and ask your CA to reissue the certificate (usually free).

Often converted to or from: PEM, DER, PFX/P12 (with certificate), PKCS#1 / PKCS#8

Frequently asked questions

Can I upload my .key file to an online tool?

Avoid it. Treat the private key like a password: anyone who has it can decrypt or impersonate your site, so inspect it locally with OpenSSL and only share the certificate or CSR.

What permissions should a private key have?

Readable only by its owner: chmod 600 (or 400), owned by root or the web server's service account, and stored outside the web root.

My .key file opens in Keynote. Is that wrong?

No. Apple Keynote presentations also use .key. If it contains slides it is a presentation; if a text editor shows BEGIN PRIVATE KEY it is a cryptographic key.

See all file types β†’ Β· Browse error fixes β†’