SSL & Security

Certificate Converter

Format Conversion
Certificate Converter
Pick your formats, then paste or upload your certificate
Convert from
Convert to
PEM (Base64 text · Apache, Nginx, OpenSSL)  →  DER (Binary · Java, Windows)
PEM
Certificate input
Options
No extra options needed for PEM → DER.
Converted in memory on the server — your certificate is never stored

Tool features

Move certificates between the formats servers expect
4 checks

Four formats, any direction

Convert between PEM, DER, PKCS#7 (P7B) and PKCS#12 (PFX) in either direction.

PFX build & extract

Bundle a certificate with its private key into a password-protected PFX, or pull the certificate and key back out.

Chains carried through

Multi-certificate PEM, P7B and PFX inputs keep their full chain in formats that support one.

Nothing stored

Conversion runs in server memory; certificates, keys and passwords are never written to disk or logged.

What are certificate formats & how conversion works

Why the same certificate ships as PEM, DER, P7B or PFX

An SSL certificate is the same data whatever file it sits in; the format only changes how it is encoded and what travels with it. Apache and Nginx expect Base64 PEM text, Java and some Windows tools want binary DER, and IIS or Azure import a single PFX that also carries the private key.

Converting re-encodes the certificate (and chain, and key where the target format holds one) without changing the certificate itself, so it stays valid and trusted. You only need to convert when a server or platform won't accept the file your CA issued.

PEM / DER
The same X.509 certificate as Base64 text (PEM) or raw binary (DER).
PKCS#7 (P7B)
A container for one or more certificates, typically a chain, with no private key.
PKCS#12 (PFX)
A password-protected bundle holding the certificate, its chain and the private key.

How to use this tool

Move a certificate between PEM, DER, P7B and PFX in four steps
1
Choose your formats
Pick the format you have and the one your server needs — for example PEM → PFX for Windows/IIS, or PFX → PEM for Apache and Nginx.
2
Paste or upload
Paste a text certificate (PEM or P7B), or upload the file. Binary formats like DER and PFX must be uploaded rather than pasted.
3
Add password or key
Reading a PFX needs its password. Building a PFX also needs the matching PEM private key so it can be bundled with the certificate.
4
Convert & download
Click Convert. Copy text output straight to your clipboard, or download the file with a name you choose — the right extension is added for you.

Frequently asked questions

Common questions about certificate format conversion
6 Q&A

PEM is Base64 text wrapped in "-----BEGIN CERTIFICATE-----" markers, used by Apache, Nginx and OpenSSL. DER is the same certificate as raw binary, common on Java and Windows. PKCS#7 (.p7b / .p7c) holds a certificate chain but no private key. PKCS#12 (.pfx / .p12) is an encrypted, password-protected bundle containing the certificate, its chain and the private key together — the format Windows/IIS and many load balancers expect.

Windows servers (IIS), Microsoft Azure and many appliances import certificates as a single password-protected .pfx that contains both the certificate and its private key. If your CA gave you a PEM certificate and a separate key file, convert them into a PFX to import them together.

A PFX bundles the certificate and its private key in one file. When you build a PFX from a format that doesn't carry the key (PEM, DER or P7B), you must supply the matching PEM private key so it can be included. Converting away from a PFX extracts the key automatically — no key input needed.

No. Conversion runs in server memory only — your certificate and private key are never written to disk, logged or retained, and are discarded as soon as the response is sent. For maximum control you can also convert locally with OpenSSL, e.g. "openssl x509 -in cert.pem -outform der -out cert.der".

The usual causes are an incorrect PFX password, a missing or mismatched private key when building a PFX, or an encrypted/EC private key. Check the password is correct, and that the PEM private key is unencrypted, RSA, and matches the certificate.

Yes. Paste a full PEM chain or upload a P7B/PFX that contains several certificates, and they're carried through to formats that support chains (PEM, P7B, PFX). DER holds a single certificate, so only the leaf certificate is exported when converting to DER.