Choose a file to convert. It's processed locally — never uploaded. Tip: add several files to convert them all at once.
Settings
Result appears here after you select
{ } How to use
- Choose the .der or .cer file.
- Pick what the file contains — a certificate, a request or a key.
- Select Process, then copy or download the PEM.
{ } How it works
DER to PEM Converter works on the file you upload. Adjust the options, then select Process ▸ and it runs entirely in your browser — nothing is uploaded to a server — then shows the result in the Output panel.
Inputs
- DER file — upload a file (.der,.cer,.crt,.key,.csr); it is read locally in your browser
- Content type — choose one — Certificate, Certificate request (CSR), Private key (PKCS#8), RSA private key (PKCS#1), EC private key (SEC1), Public key (default: Certificate)
Output
TXT text — copy or download it from the Output panel.
{ } Common uses
- Install a certificate on a web server that only reads PEM.
- Turn a binary certificate into something you can paste into a decoder or an email.
{ } Limitations
- You have to say what the file holds. A certificate and a signing request are both a SEQUENCE of the same three parts at the byte level, so nothing in the file reliably distinguishes them, and guessing would put the wrong label on your key.
- A DER file that is already PEM, or that is not DER at all, is rejected rather than wrapped in a misleading label.
{ } FAQ
Is my data uploaded to a server?
No. Everything runs locally in your browser — your files never leave your device.
Can I process more than one file at once?
Yes — add several files and they’re all processed and downloaded together as a ZIP.
Is this tool free?
Yes — it’s completely free and needs no sign-up.
Which content type should I choose?
Whatever the file was exported as. A .cer or .crt from an authority is almost always a certificate; a .key is a private key. If you pick wrongly the PEM will carry the wrong label, and whatever reads it next will refuse it.
Is my private key uploaded anywhere?
No. Every one of these tools runs entirely in your browser — the certificate and key are read, converted and shown without a byte being sent anywhere. That is what makes it safe to paste a private key, which you should never do on a site that converts it on a server.
Does this work with ECDSA certificates?
Yes. RSA, ECDSA and Ed25519 are all read the same way, because the structure is read directly rather than through a library that only understands RSA keys.