Key facts
- Binary PKCS#12 format (RFC 7292); MIME type application/x-pkcs12.
- Contains the private key, so it is protected by an import password and must be handled as a secret.
- Typically 2-10 KB depending on how many chain certificates are included.
- Exported from Windows certificate manager, IIS, Azure Key Vault, or created with openssl pkcs12 -export.
How to open a .pfx file
Double-click it to start the Certificate Import Wizard, enter the password and choose the store, or use certlm.msc and IIS Manager for server certificates.
Double-click it to import into Keychain Access with the password. In Terminal, list its contents with openssl pkcs12 -in site.pfx -info -nokeys.
Extract the certificate with openssl pkcs12 -in site.pfx -clcerts -nokeys -out cert.pem and the key with openssl pkcs12 -in site.pfx -nocerts -nodes -out key.pem.
Common problems and fixes
- OpenSSL 3: 'unsupported' or 'RC2-40-CBC' error
- The PFX uses legacy encryption that OpenSSL 3 disables by default. Add -legacy to the openssl pkcs12 command.
- Windows Server rejects a PFX made with OpenSSL 3 ('password incorrect')
- Older Windows versions cannot read the AES-based defaults. Re-export with openssl pkcs12 -export -legacy ... or use -certpbe PBE-SHA1-3DES -keypbe PBE-SHA1-3DES -macalg sha1.
- Imported certificate has no private key
- The PFX was exported without the key, or the key was marked non-exportable. Re-export from the original machine with 'Yes, export the private key' selected.
- Chain is missing on the server after import
- The bundle did not include intermediates. Create a new PFX with -certfile chain.pem, or install the intermediate certificates separately.
Often converted to or from: PEM (cert + key), CRT, KEY, JKS (Java keystore)