Certificate Key Matcher

Paste a certificate and a private key to see instantly whether they belong together. Start here when Nginx reports "key values mismatch" or an IIS or Tomcat import fails.

Everything runs in your browser. Your certificate and private key are never sent to LapseZero or any third party, and nothing is left behind when you close the page.

When to check a certificate and private key

Nginx says "key values mismatch"

If nginx -t or a restart fails with SSL_CTX_use_PrivateKey failed … key values mismatch, or Apache logs AH02565 Certificate and private key do not match, the configured certificate and key aren't a pair. Paste both files to see whether it's the wrong key or a chain in the wrong order.

IIS or Tomcat import fails

Building a PFX or JKS fails with a key mismatch, or IIS imports the certificate without a private key and can't bind it to a site. The root cause is often a certificate and key from different sets. Confirm the match here, then create the PFX or JKS with the certificate converter.

Several sets of files after renewal

After renewals, reissues or several domains, it's easy to lose track of which .key goes with which .crt. Compare them one by one; the result shows the domain, expiry date and key type so you know which set you have.

FAQ

Is it safe? Is my private key uploaded?
No upload. The check runs entirely in your browser: the public key is derived from the private key and compared byte by byte with the certificate's public key. Neither file is sent to LapseZero or any third party, and nothing is kept after you close the page. You can verify this in your browser's developer tools: clicking Check makes no network requests.
The certificate and key are a pair. Why does Nginx still say "key values mismatch"?
Check the certificate order in the file that ssl_certificate points to. Nginx compares the key with the first certificate in that file, so a full chain must start with the domain certificate followed by intermediates. If an intermediate comes first, Nginx fails even with the right key. Paste the whole fullchain.pem into the Certificate box and the tool will flag the order; the SSL Certificate Decoder & Chain Builder can also generate a correctly ordered file.
Can I check whether a CSR matches a private key?
Yes. Paste the CSR (BEGIN CERTIFICATE REQUEST) into the Certificate box. Checking before you submit the CSR saves you from discovering a mismatched key after the certificate is issued. Generate and save the CSR and key together; the CSR Generator does this in your browser.
What if my private key is encrypted?
Keys that start with BEGIN ENCRYPTED PRIVATE KEY or contain Proc-Type: 4,ENCRYPTED are password-protected. For safety this tool doesn't accept key passwords, so decrypt it locally first: openssl pkey -in key.pem -out key-plain.pem (you'll be asked for the password), then paste the decrypted key. Note that Nginx also needs ssl_password_file to read an encrypted key.
What if I can't find the matching private key?
A private key can't be recovered from a certificate or CSR. Look where the CSR was generated: the .key file on your server, the certificate folder of your hosting panel, or your provider's console (some providers offer the key for download when they generate the CSR for you). If it's truly gone, generate a new CSR and key with the CSR Generator and have the certificate reissued; most providers reissue for free.
What are the equivalent OpenSSL commands?
Hash the public key of each file; identical results mean a match: openssl x509 -noout -pubkey -in cert.pem | openssl sha256 openssl pkey -pubout -in key.pem | openssl sha256 For a CSR: openssl req -noout -pubkey -in request.csr | openssl sha256 The commonly cited -modulus comparison only works for RSA; use the commands above for ECDSA.

Done chasing certificate and key mismatches? Let LapseZero handle it

LapseZero generates the key, issues the certificate and deploys them together to your servers and cloud services on every renewal, so the wrong key never ends up in production. Start on the free plan.

Start for free