Key facts
- Text format defined in RFC 7468; the BEGIN label says what is inside (CERTIFICATE, PRIVATE KEY, CERTIFICATE REQUEST, ...).
- One file can hold several blocks, such as a leaf certificate followed by intermediate certificates.
- Commonly served as application/x-pem-file; the same Base64-encoded DER data also appears as .crt, .cer and .key.
- A single certificate is typically 1-3 KB; private keys can be encrypted with a passphrase.
How to open a .pem file
Open it in Notepad to see which BEGIN blocks it contains. For a certificate, run certutil -dump file.pem, or copy it to a .crt name and double-click to use the Certificate viewer.
Inspect it in Terminal with openssl x509 -in cert.pem -noout -text, or import a certificate into Keychain Access to view its details. Never import keys you do not need to.
Run openssl x509 -in cert.pem -noout -subject -issuer -dates -ext subjectAltName for certificates, or openssl pkey -in key.pem -noout for keys.
Common problems and fixes
- 'unable to load certificate' or 'no start line'
- The file is binary DER, contains extra text, or has a broken BEGIN line. Convert DER with openssl x509 -inform der -in cert.der -out cert.pem, or remove stray characters and BOMs.
- Browser says the certificate chain is incomplete
- The server is sending only the leaf certificate. Use a file with the leaf first, followed by its intermediates (Let's Encrypt's fullchain.pem), and reload the server.
- Private key does not match certificate
- Compare public keys: openssl x509 -in cert.pem -noout -pubkey and openssl pkey -in key.pem -pubout must print identical output. If not, find the key used to create the CSR or reissue the certificate.
- Server asks for a passphrase on every restart
- The private key is encrypted. Store a decrypted copy (openssl pkey -in enc.pem -out key.pem) with permissions 600, or configure the server's passphrase dialog.
Often converted to or from: CRT/CER, DER, PFX/P12, KEY