Ffile2fix
Sign in Get started

What is a .pem file?

A .pem file is a Base64 text container for cryptographic material: TLS certificates, certificate chains, private keys or CSRs, wrapped in -----BEGIN ...----- and -----END ...----- lines. Web servers like Nginx and Apache, Let's Encrypt (fullchain.pem, privkey.pem) and SSH tools all use it.

Key facts

  • Text format defined in RFC 7468; the BEGIN label says what is inside (CERTIFICATE, PRIVATE KEY, CERTIFICATE REQUEST, ...).
  • One file can hold several blocks, such as a leaf certificate followed by intermediate certificates.
  • Commonly served as application/x-pem-file; the same Base64-encoded DER data also appears as .crt, .cer and .key.
  • A single certificate is typically 1-3 KB; private keys can be encrypted with a passphrase.

How to open a .pem file

Windows

Open it in Notepad to see which BEGIN blocks it contains. For a certificate, run certutil -dump file.pem, or copy it to a .crt name and double-click to use the Certificate viewer.

macOS

Inspect it in Terminal with openssl x509 -in cert.pem -noout -text, or import a certificate into Keychain Access to view its details. Never import keys you do not need to.

Linux

Run openssl x509 -in cert.pem -noout -subject -issuer -dates -ext subjectAltName for certificates, or openssl pkey -in key.pem -noout for keys.

Common problems and fixes

'unable to load certificate' or 'no start line'
The file is binary DER, contains extra text, or has a broken BEGIN line. Convert DER with openssl x509 -inform der -in cert.der -out cert.pem, or remove stray characters and BOMs.
Browser says the certificate chain is incomplete
The server is sending only the leaf certificate. Use a file with the leaf first, followed by its intermediates (Let's Encrypt's fullchain.pem), and reload the server.
Private key does not match certificate
Compare public keys: openssl x509 -in cert.pem -noout -pubkey and openssl pkey -in key.pem -pubout must print identical output. If not, find the key used to create the CSR or reissue the certificate.
Server asks for a passphrase on every restart
The private key is encrypted. Store a decrypted copy (openssl pkey -in enc.pem -out key.pem) with permissions 600, or configure the server's passphrase dialog.

Often converted to or from: CRT/CER, DER, PFX/P12, KEY

Frequently asked questions

Is a .pem file a certificate or a private key?

It can be either, or both. Open it in a text editor and read the BEGIN lines: CERTIFICATE is public, while PRIVATE KEY (or RSA/EC PRIVATE KEY) is secret and must never be shared.

What is the difference between .pem and .crt?

PEM is an encoding; .crt is just a naming convention for certificates, which may be PEM or binary DER. A PEM certificate can be renamed to .crt without conversion.

How do I check when a PEM certificate expires?

Run openssl x509 -in cert.pem -noout -enddate, or paste the certificate into a decoder. Live sites can be checked by connecting to the host instead.

See all file types β†’ Β· Browse error fixes β†’