How to convert .pem into .key?

前端 未结 6 1202
梦如初夏
梦如初夏 2021-01-30 01:38

I already have purchased SSL certificate and i have received certificate and a .pem file as a private key? from the supplier; now i need to convert this .pem key into .key for b

相关标签:
6条回答
  • 2021-01-30 01:53

    openssl rsa -in privkey.pem -out private.key does the job.

    0 讨论(0)
  • 2021-01-30 01:59

    CA's don't ask for your private keys! They only asks for CSR to issue a certificate for you.

    If they have your private key, it's possible that your SSL certificate will be compromised and end up being revoked.

    Your .key file is generated during CSR generation and, most probably, it's somewhere on your PC where you generated the CSR.

    That's why private key is called "Private" - because nobody can have that file except you.

    0 讨论(0)
  • 2021-01-30 02:12

    I assume you want the DER encoded version of your PEM private key.

    openssl rsa -outform der -in private.pem -out private.key
    
    0 讨论(0)
  • 2021-01-30 02:12

    If you're looking for a file to use in httpd-ssl.conf as a value for SSLCertificateKeyFile, a PEM file should work just fine.

    See this SO question/answer for more details on the SSL options in that file.

    Why is SSLCertificateKeyFile needed for Apache?

    0 讨论(0)
  • 2021-01-30 02:13

    just as a .crt file is in .pem format, a .key file is also stored in .pem format. Assuming that the cert is the only thing in the .crt file (there may be root certs in there), you can just change the name to .pem. The same goes for a .key file. Which means of course that you can rename the .pem file to .key.

    Which makes gtrig's answer the correct one. I just thought I'd explain why.

    0 讨论(0)
  • 2021-01-30 02:14
    openssl x509 -outform der -in your-cert.pem -out your-cert.crt
    
    0 讨论(0)
提交回复
热议问题