SSL & Certificates

PFX to PEM Converter

Unpack a password-protected .pfx or .p12 file into the separate PEM certificate and private key that Apache and nginx expect.

PKCS#12 file

Choose a file to convert. It's processed locally — never uploaded. Tip: add several files to convert them all at once.

Settings

Output

Result appears here after you select

{ } How to use

  1. Choose the .pfx or .p12 file.
  2. Enter the password it was exported with.
  3. Select Process, then copy or download the PEM bundle.

{ } How it works

PFX to PEM Converter works on the file you upload. Adjust the options, then select Process ▸ and it runs entirely in your browser — nothing is uploaded to a server — then shows the result in the Output panel.

Inputs

  • PKCS#12 file — upload a file (.pfx,.p12); it is read locally in your browser
  • Password — a value

Output

TXT text — copy or download it from the Output panel.

{ } Common uses

  • Move a certificate from Windows or IIS to nginx, Apache or a load balancer.
  • Extract the private key and certificate from a backup you were given as one file.
  • Split a supplier’s .pfx into the parts a Linux server wants.

{ } Limitations

  • The private key in the output is not encrypted — that is what a server needs, but it means the result is as sensitive as a password. Save it somewhere safe and delete any stray copy.
  • The export password is required; there is no way to open a PKCS#12 file without it, here or anywhere.

{ } FAQ

Is my data uploaded to a server?

No. Everything runs locally in your browser — your files never leave your device.

Can I process more than one file at once?

Yes — add several files and they’re all processed and downloaded together as a ZIP.

Is this tool free?

Yes — it’s completely free and needs no sign-up.

Is it safe to open my .pfx here?

Yes, in the specific sense that matters: the file and its password never leave your browser. The conversion happens on your own machine, so no server ever sees the key. Treat the output as a secret all the same.

Is my private key uploaded anywhere?

No. Every one of these tools runs entirely in your browser — the certificate and key are read, converted and shown without a byte being sent anywhere. That is what makes it safe to paste a private key, which you should never do on a site that converts it on a server.

Does this work with ECDSA certificates?

Yes. RSA, ECDSA and Ed25519 are all read the same way, because the structure is read directly rather than through a library that only understands RSA keys.