SSL Format Converter

All computation runs locally in your browser. Private keys and CSRs never leave your device, and we never collect or store them.

About SSL Format Converter

The CSR.plus SSL Format Converter translates certificates and keys between PEM, DER, PFX/PKCS#12, and P7B/PKCS#7 encodings. Whether you need a .crt for Apache, a Base64 string for Kubernetes, or a .pfx for Windows Server, the converter re-encodes your material locally and produces a ready-to-use download — no server round-trip.

Every platform expects certificates in a different container format, and converting between PEM, DER, PKCS#12, and PKCS#7 is a constant need when moving certificates between web servers, load balancers, mail servers, and cloud platforms. This online converter performs the conversion in your browser so private keys inside a PKCS#12 file never leave your machine.

Why use

  • Convert between PEM, DER, PFX/PKCS#12, and P7B/PKCS#7 formats
  • Export ready-to-use files for Apache, Nginx, IIS, and Kubernetes
  • Set or remove the passphrase on PKCS#12 containers
  • Private keys are processed locally and never uploaded

How to use

  1. Upload or paste the certificate or key you want to convert.
  2. Select the source format — auto-detected from the content when possible.
  3. Choose the target format (for example PEM to PFX, or P7B to PEM).
  4. Download the converted file or copy the result instantly.

Frequently asked questions

▸Which formats can I convert between?

PEM text, DER binary, PFX/PKCS#12, and P7B/PKCS#7, for certificates, CSRs, and keys.

▸Is conversion done locally?

Yes. Encoding and decoding happen in your browser; files are never uploaded.

▸Will the converted file keep the private key?

Yes, if you convert a key or a PKCS#12 container, the private material is preserved in the new encoding.

▸Why do I need to convert between PEM and PFX?

Linux servers (Apache, Nginx) expect PEM or CRT files, while Windows Server and IIS typically import PFX/PKCS#12 containers. Converting between them is required when moving certificates across platforms.

Namecheap

Need a new SSL certificate?

DV, OV, EV and wildcard certificates from just $5.98/yr — issued in minutes.

Get SSL on Namecheap

Affiliate link — we may earn a commission at no extra cost to you.

More free tools

Certificate Viewer

Paste or upload an X.509 certificate to inspect its subject, issuer, validity, key, fingerprints, SAN and extensions — all locally.

Certificate / Key Matcher

Check whether a private key and a certificate belong to the same key pair — computed locally, the key never leaves your browser.

PEM Viewer

Paste a PEM bundle (certificates, keys, CSRs) and see a structured breakdown of every block — locally.

SSL Checker (A-F Grade)

Grade any domain from A to F: TLS versions, certificate health, chain trust and HSTS.

SSL Bulk Checker

Check multiple SSL certificates at once

ACME Challenge Preflight

Test HTTP-01 and DNS-01 validation before Let's Encrypt does: DNS, port 443, well-known reachability and TXT records with fix suggestions.

Let's Encrypt Checker

Detect Let's Encrypt certificates (R3/R10/E5/E6), see the 90-day renewal countdown, chain health and renewal advice.

DNS Propagation Checker

Check TXT, A, AAAA, NS and MX records across Cloudflare, Google and AdGuard resolvers and confirm propagation.

LE Chain Compatibility

See whether your site serves the new ISRG E5/E6 chain or the legacy cross-signed chain and whether old devices trust it.

ACME Command Generator

Generate copy-paste issuance commands for Certbot, acme.sh, lego and win-acme with HTTP-01 or DNS-01.

Certificate Inspector

Enter a domain to inspect certificate validity, expiry, TLS protocol and full chain integrity.

SSL Expiry Checker

Quickly check a domain's SSL certificate expiry date and remaining days.

Certificate Transparency Lookup

List every certificate ever issued for a domain in public CT logs — discover shadow and unauthorized certs.

CAA Record Checker

Query a domain's DNS CAA records to see which Certificate Authorities are allowed to issue certificates for it.

Certificate Revocation Checker

Verify whether a certificate has been revoked via its CRL distribution points, and view embedded OCSP endpoints.

SSL Handshake Tracer

Perform a real TLS handshake and record every step: DNS, TCP, negotiated TLS version and cipher, and each certificate returned.