Ffile2fix
Sign in Get started

What is a .pfx file?

A .pfx file (also .p12) is a password-protected PKCS#12 bundle that packs a certificate, its private key and usually the intermediate chain into one binary file. It is the standard way to move SSL certificates to and from Windows, IIS, Azure and Java keystores.

Key facts

  • Binary PKCS#12 format (RFC 7292); MIME type application/x-pkcs12.
  • Contains the private key, so it is protected by an import password and must be handled as a secret.
  • Typically 2-10 KB depending on how many chain certificates are included.
  • Exported from Windows certificate manager, IIS, Azure Key Vault, or created with openssl pkcs12 -export.

How to open a .pfx file

Windows

Double-click it to start the Certificate Import Wizard, enter the password and choose the store, or use certlm.msc and IIS Manager for server certificates.

macOS

Double-click it to import into Keychain Access with the password. In Terminal, list its contents with openssl pkcs12 -in site.pfx -info -nokeys.

Linux

Extract the certificate with openssl pkcs12 -in site.pfx -clcerts -nokeys -out cert.pem and the key with openssl pkcs12 -in site.pfx -nocerts -nodes -out key.pem.

Common problems and fixes

OpenSSL 3: 'unsupported' or 'RC2-40-CBC' error
The PFX uses legacy encryption that OpenSSL 3 disables by default. Add -legacy to the openssl pkcs12 command.
Windows Server rejects a PFX made with OpenSSL 3 ('password incorrect')
Older Windows versions cannot read the AES-based defaults. Re-export with openssl pkcs12 -export -legacy ... or use -certpbe PBE-SHA1-3DES -keypbe PBE-SHA1-3DES -macalg sha1.
Imported certificate has no private key
The PFX was exported without the key, or the key was marked non-exportable. Re-export from the original machine with 'Yes, export the private key' selected.
Chain is missing on the server after import
The bundle did not include intermediates. Create a new PFX with -certfile chain.pem, or install the intermediate certificates separately.

Often converted to or from: PEM (cert + key), CRT, KEY, JKS (Java keystore)

Frequently asked questions

What is the difference between .pfx and .p12?

None in practice: both are PKCS#12 files. Windows tools favour .pfx, while macOS, Java and many Linux tools use .p12.

How do I create a PFX from my certificate and key?

Run openssl pkcs12 -export -out site.pfx -inkey server.key -in server.crt -certfile chain.pem and set an export password. Add -legacy if the file must import on older Windows versions.

I forgot the PFX password. Can I recover it?

Not practically; the password protects the private key. Export a new PFX from the system where the certificate is installed, or reissue the certificate with a new key.

See all file types β†’ Β· Browse error fixes β†’