For the complete documentation index, see llms.txt. This page is also available as Markdown.

Extract CRT and KEY Files from a PFX Certificate

Learn how to extract .crt and .key files from a .pfx certificate using OpenSSL.

A PKCS#12 (.pfx) file contains a certificate, private key, and optional intermediate certificates in a single encrypted bundle. Although the SSL / TLS wizard supports uploading .pfx files directly, some environments or workflows require separate .crt and .key files.

This guide explains how to extract the certificate and private key from a PKCS#12 file using OpenSSL.

This procedure is optional. If your certificate is already available as a PKCS#12 (.pfx) file, you can upload it directly using the Upload PKCS#12 (.pfx) option in the SSL / TLS wizard.

Prerequisites

Before you begin, ensure that you have:

  • A valid PKCS#12 (.pfx) certificate file.

  • The password protecting the .pfx file.

  • OpenSSL installed on your system.

  • (Optional) A descriptive filename such as example_com.pfx.

1

Create the Extraction Script

Create a new Bash script named extract-cert.sh and paste the following content.

#!/bin/bash
# Usage: ./extract-cert.sh <pfx-password>

# 1. Extract encrypted private key
openssl pkcs12 -in domain.pfx -nocerts -out encrypted-domain.key -passin pass:$1 -passout pass:$1

# 2. Decrypt the private key
openssl rsa -in encrypted-domain.key -out domain.key -passin pass:$1

# 3. Extract public certificate
openssl pkcs12 -in domain.pfx -clcerts -nokeys -out domain.crt -passin pass:$1

# 4. Verify that the certificate and key match
first=$(openssl x509 -in domain.crt -modulus -noout | openssl md5)
second=$(openssl rsa -in domain.key -modulus -noout | openssl md5)

if [[ "$first" == "$second" ]]; then
    echo "✅ Certificate and Key match."
else
    echo "❌ Mismatch between certificate and key."
fi

Save the file after replacing domain.pfx with your actual filename.

For example, if your certificate file is named medianova_com.pfx, update the script accordingly before running it.

2

Make the Script Executable

Grant execute permission to the script.

chmod +x extract-cert.sh

This command allows the script to be executed from the command line.

3

Run the Script

Run the script and provide the password for your PKCS#12 file.

./extract-cert.sh yourPFXpassword

Replace yourPFXpassword with the actual password for the .pfx file.

The script extracts the certificate and private key, then verifies that they belong to the same certificate pair.

4

Review the Generated Files

After the script finishes successfully, the following files are created.

File
Description

domain.crt

Public certificate.

domain.key

Unencrypted private key.

encrypted-domain.key

Temporary encrypted private key. This file can be deleted after verification.

5

Verify the Results

If the extraction succeeds, the script prints:

✅ Certificate and Key match.

If the certificate and private key do not belong to the same certificate:

❌ Mismatch between certificate and key.

If a mismatch is reported, verify that you are using the correct .pfx file and password before repeating the extraction process.

Next Steps

After extracting the files, you can use either of the following options in the SSL / TLS wizard:

  • Upload Certificate Files to upload the generated .crt and .key files.

  • Paste Certificate and Private Key to paste their contents directly into the wizard.

If you do not need separate certificate files, upload the original .pfx file directly using the Upload PKCS#12 (.pfx) option.

Last updated

Was this helpful?