Settings
Result appears here after you select
{ } How to use
- Paste the certificate and the private key together, each with its own BEGIN and END lines. Add any intermediate certificates after the first one.
- Choose an export password — you will need it to import the file.
- Select Process, then download the .pfx.
{ } How it works
PEM to PFX Converter works on the text you provide. Adjust the options, then select Process ▸ and it runs entirely in your browser — nothing is uploaded to a server — then shows the result in the Output panel.
Inputs
- Certificate and private key — paste or type your input in the left panel (use Sample for an example)
- Password — a value
- Encryption — choose one — 3DES — widest compatibility, AES-256 — stronger (default: 3DES — widest compatibility)
Output
PFX text — copy or download it from the Output panel.
{ } Common uses
- Import a certificate bought for a Linux server into IIS or Windows.
- Bundle a certificate, its chain and key into the single file a Java keystore wants.
- Hand a certificate to someone as one password-protected file instead of three.
{ } Limitations
- The private key must be unencrypted. A key that is itself password-protected has to be decrypted first.
- 3DES is the default because almost every keystore, server and version of Windows can read it. AES-256 is stronger, but older tools — Java 8 and some Windows versions among them — will refuse a file that uses it.
- The password is what protects the key inside the file, so a weak one leaves the key effectively unprotected.
{ } FAQ
Is my data uploaded to a server?
No. Everything runs locally in your browser — your files never leave your device.
Can I process more than one file at once?
This tool works on one input at a time.
Is this tool free?
Yes — it’s completely free and needs no sign-up.
In what order should I paste things?
Certificate first, then any intermediates, then the private key. The order of the blocks is what tells the file which certificate the key belongs to.
Can I build a .pfx without a private key?
Yes — paste only certificates and you get a file holding just those, which is what some systems want for a chain. It still needs a password.
Is my private key uploaded anywhere?
No. Every one of these tools runs entirely in your browser — the certificate and key are read, converted and shown without a byte being sent anywhere. That is what makes it safe to paste a private key, which you should never do on a site that converts it on a server.
Does this work with ECDSA certificates?
Yes. RSA, ECDSA and Ed25519 are all read the same way, because the structure is read directly rather than through a library that only understands RSA keys.