SSL Format Converter
All computation runs locally in your browser. Private keys and CSRs never leave your device, and we never collect or store them.
About SSL Format Converter
The CSR.plus SSL Format Converter translates certificates and keys between PEM, DER, PFX/PKCS#12, and P7B/PKCS#7 encodings. Whether you need a .crt for Apache, a Base64 string for Kubernetes, or a .pfx for Windows Server, the converter re-encodes your material locally and produces a ready-to-use download — no server round-trip.
Every platform expects certificates in a different container format, and converting between PEM, DER, PKCS#12, and PKCS#7 is a constant need when moving certificates between web servers, load balancers, mail servers, and cloud platforms. This online converter performs the conversion in your browser so private keys inside a PKCS#12 file never leave your machine.
Why use
- Convert between PEM, DER, PFX/PKCS#12, and P7B/PKCS#7 formats
- Export ready-to-use files for Apache, Nginx, IIS, and Kubernetes
- Set or remove the passphrase on PKCS#12 containers
- Private keys are processed locally and never uploaded
How to use
- Upload or paste the certificate or key you want to convert.
- Select the source format — auto-detected from the content when possible.
- Choose the target format (for example PEM to PFX, or P7B to PEM).
- Download the converted file or copy the result instantly.
Frequently asked questions
▸Which formats can I convert between?
PEM text, DER binary, PFX/PKCS#12, and P7B/PKCS#7, for certificates, CSRs, and keys.
▸Is conversion done locally?
Yes. Encoding and decoding happen in your browser; files are never uploaded.
▸Will the converted file keep the private key?
Yes, if you convert a key or a PKCS#12 container, the private material is preserved in the new encoding.
▸Why do I need to convert between PEM and PFX?
Linux servers (Apache, Nginx) expect PEM or CRT files, while Windows Server and IIS typically import PFX/PKCS#12 containers. Converting between them is required when moving certificates across platforms.
Namecheap
Need a new SSL certificate?
DV, OV, EV and wildcard certificates from just $5.98/yr — issued in minutes.
Affiliate link — we may earn a commission at no extra cost to you.
More free tools
Certificate Viewer
Paste or upload an X.509 certificate to inspect its subject, issuer, validity, key, fingerprints, SAN and extensions — all locally.
Certificate / Key Matcher
Check whether a private key and a certificate belong to the same key pair — computed locally, the key never leaves your browser.
PEM Viewer
Paste a PEM bundle (certificates, keys, CSRs) and see a structured breakdown of every block — locally.
SSL Checker (A-F Grade)
Grade any domain from A to F: TLS versions, certificate health, chain trust and HSTS.
SSL Bulk Checker
Check multiple SSL certificates at once
ACME Challenge Preflight
Test HTTP-01 and DNS-01 validation before Let's Encrypt does: DNS, port 443, well-known reachability and TXT records with fix suggestions.
Let's Encrypt Checker
Detect Let's Encrypt certificates (R3/R10/E5/E6), see the 90-day renewal countdown, chain health and renewal advice.
DNS Propagation Checker
Check TXT, A, AAAA, NS and MX records across Cloudflare, Google and AdGuard resolvers and confirm propagation.
LE Chain Compatibility
See whether your site serves the new ISRG E5/E6 chain or the legacy cross-signed chain and whether old devices trust it.
ACME Command Generator
Generate copy-paste issuance commands for Certbot, acme.sh, lego and win-acme with HTTP-01 or DNS-01.
Certificate Inspector
Enter a domain to inspect certificate validity, expiry, TLS protocol and full chain integrity.
SSL Expiry Checker
Quickly check a domain's SSL certificate expiry date and remaining days.
Certificate Transparency Lookup
List every certificate ever issued for a domain in public CT logs — discover shadow and unauthorized certs.
CAA Record Checker
Query a domain's DNS CAA records to see which Certificate Authorities are allowed to issue certificates for it.
Certificate Revocation Checker
Verify whether a certificate has been revoked via its CRL distribution points, and view embedded OCSP endpoints.
SSL Handshake Tracer
Perform a real TLS handshake and record every step: DNS, TCP, negotiated TLS version and cipher, and each certificate returned.