使用openssl将pfx转换为pem

new*_*bie 100 openssl pfx pem

如何使用OpenSSL从PFX文件生成.pem CA证书和客户端证书.

use*_*376 174

在Linux上执行此操作的另一个视角...这里是如何做到这一点,以便生成的单个文件包含解密的私钥,以便像HAProxy这样的东西可以使用它而不会提示您输入密码.

openssl pkcs12 -in file.pfx -out file.pem -nodes
Run Code Online (Sandbox Code Playgroud)

然后,您可以配置HAProxy以使用file.pem文件.


这是以前版本的编辑,我有这几个步骤,直到我意识到-nodes选项只是简单地绕过私钥加密.但是我把它留在这里,因为它可能只对教学有帮助.

openssl pkcs12 -in file.pfx -out file.nokey.pem -nokeys
openssl pkcs12 -in file.pfx -out file.withkey.pem
openssl rsa -in file.withkey.pem -out file.key
cat file.nokey.pem file.key > file.combo.pem
Run Code Online (Sandbox Code Playgroud)
  1. 第1步提示您输入密码以打开PFX.
  2. 第二步提示您加上该密钥以及密钥的密码短语.
  3. 第3步提示您输入刚刚存储解密的密码.
  4. 第4个将它们整合成1个文件.

然后,您可以配置HAProxy以使用file.combo.pem文件.

您需要两个单独的步骤来指示带有密钥的文件而另一个没有密钥的原因是因为如果您有一个同时具有加密和解密密钥的文件,HAProxy之类的内容仍会提示您在密码时输入密码.它使用它.

  • 在 Windows 系统上使用 type 而不是 cat (2认同)
  • 在 Windows 上,此版本的 OpenSSL 很容易用于以下用途:http://slproweb.com/products/Win32OpenSSL.html (2认同)

Jay*_*Jay 100

您可以使用OpenSSL命令行工具.以下命令应该可以解决问题

openssl pkcs12 -in client_ssl.pfx -out client_ssl.pem -clcerts

openssl pkcs12 -in client_ssl.pfx -out root.pem -cacerts
Run Code Online (Sandbox Code Playgroud)

如果您希望您的文件受密码保护等,那么还有其他选项.

您可以在此处阅读整个文档.


Moh*_*din 36

尽管其他答案是正确的并且得到了彻底的解释,但我发现理解它们有些困难。这是我使用的方法(取自此处):

第一种情况:将 PFX 文件转换为包含证书和私钥的 PEM 文件:

openssl pkcs12 -in filename.pfx -out cert.pem -nodes
Run Code Online (Sandbox Code Playgroud)

第二种情况:要将 PFX 文件转换为单独的公钥和私钥 PEM 文件:

将私钥从 PFX 提取到 PEM 文件:

openssl pkcs12 -in filename.pfx -nocerts -out key.pem
Run Code Online (Sandbox Code Playgroud)

导出证书(仅包含公钥):

openssl pkcs12 -in filename.pfx -clcerts -nokeys -out cert.pem
Run Code Online (Sandbox Code Playgroud)

从提取的私钥(可选)中删除密码(意译):

openssl rsa -in key.pem -out server.key
Run Code Online (Sandbox Code Playgroud)

  • @openCivilization 您可以通过在“pkcs12”后面添加“-nodes”来禁用 key.pem 的 PEM 密码短语设置 (9认同)
  • 在第一种情况下,即使原始证书没有密码,系统也会提示我输入密码。 (4认同)
  • 如果有人想知道,-nodes 的意思是“no des”,而不是英语单词“note”。请参阅 /sf/ask/353615881/ (2认同)

iam*_*991 6

您可以使用它从 .pfx 中提取 ca-bundle、.crt 和 .key。

# Extracting ca-certs..."
  openssl pkcs12 -in ${filename}.pfx -nodes -nokeys -cacerts -out ${filename}-ca.crt

# Extracting key file..."
  openssl pkcs12 -in ${filename}.pfx -nocerts -out ${filename}.key

# Extracting crt..."
  openssl pkcs12 -in ${filename}.pfx -clcerts -nokeys -out ${filename}.crt

# combine ca-certs and cert files
  cat  ${filename}.crt ${filename}-ca.crt > ${filename}-full.crt

# Removing passphrase from keyfile"
  openssl rsa -in ${filename}.key -out ${filename}.key
Run Code Online (Sandbox Code Playgroud)

链接:https ://gist.github.com/mediaupstream/a2694859b1afa59f26be5e8f6fd4806a