SSL Certificate Converter

Convert between PEM, PFX (P12), JKS and DER for IIS, Tomcat and Nginx. Upload a file or paste text, then download the result.

Conversion happens entirely in your browser. Certificates, private keys and passwords are never sent to LapseZero or anyone else, and nothing is kept after you close the page.

You'll enter this password when importing the certificate into IIS or Windows.

Which format does your server need?

IIS / Windows: PFX

IIS and the Windows certificate manager import server certificates as PFX (.pfx / .p12), which bundles the certificate, private key and intermediates into one password-protected file. If you have a PEM certificate and key, pick IIS / Windows under "Convert for", set a password, download, import it under Server Certificates in IIS Manager, then select it for https in the site's Bindings. PFX files from this tool use encryption that older Windows accepts, so they import on Windows Server 2016 and earlier too.

Tomcat / Java: PFX or JKS

Every Tomcat version can use a PFX directly: pick IIS / Windows under "Convert for", then set certificateKeystoreType="PKCS12" in server.xml (keystoreType="PKCS12" before Tomcat 8.5). Only pick Tomcat / Java when an app specifically requires JKS, and note the password and alias for certificateKeystorePassword and certificateKeyAlias.

Nginx / Apache: PEM

In Nginx, ssl_certificate points to the full chain (certificate + intermediates) and ssl_certificate_key to the private key. Apache 2.4.8 and later likewise take the full chain in SSLCertificateFile and the key in SSLCertificateKeyFile; older versions take the certificate and the intermediate chain separately in SSLCertificateFile and SSLCertificateChainFile. If all you have is a PFX or JKS, upload it and pick Nginx / Apache to download these files.

How the four formats differ

PEM (.pem / .crt / .key)
Base64 text that starts with a -----BEGIN line such as BEGIN CERTIFICATE, BEGIN PRIVATE KEY or BEGIN RSA PRIVATE KEY, readable in any text editor. The certificate, key and intermediates can live in separate files or together in one. Used by Nginx, Apache, most Linux software and cloud platforms.
DER (.der / .cer)
The binary form of PEM: PEM is just DER encoded as Base64 with BEGIN / END lines added. DER isn't human-readable and holds one certificate or key per file, common when importing a single certificate on Windows or Java. Note that the extension doesn't tell you the format: a .cer or .crt file can be either DER or PEM. If you see BEGIN when opening it in a text editor, it's PEM.
PFX / PKCS#12 (.pfx / .p12)
Bundles the certificate, private key and intermediates into one password-protected binary file. Supported by IIS, Windows, Azure, Tomcat and other Java apps.
JKS (.jks)
Java's own keystore format, also password-protected, holding a private key and its certificate chain. Java 9 switched the default keystore to PKCS#12 (PFX), so prefer PFX for new deployments; some older Java apps and middleware still require JKS.

FAQ

Is online conversion safe? Is my private key uploaded?
No. Conversion happens entirely in your browser. Certificates, private keys and passwords are never sent to LapseZero or anyone else, and nothing is kept after you close the page. If you want to be sure, check your browser's Network panel yourself.
What if my PFX or JKS password is rejected?
Make sure it's the password set when the file was exported, including case and spaces. If the PFX was exported without a password, leave the field empty and try again. PFX files downloaded from cloud providers usually ship with the password in a txt file in the same archive. For JKS, the key password must match the keystore password.
Why does it say the certificate and private key don't match?
The private key must be the one used to create this certificate's CSR. Usually an old key is still in use after a renewal or reissue, or files from different certificates got mixed up. Find the key generated together with this certificate and try again.
Browsers or phones say the certificate isn't trusted after deployment. What now?
Most often the server is configured with the certificate but not the intermediates. Desktop browsers can sometimes fill in missing intermediates, but phones, mini programs and API clients usually can't, which is why it works on a computer and fails on a phone. Paste the certificate together with its intermediates and convert: use the full chain file for Nginx or Apache, and PFX or JKS will bundle the intermediates automatically. If you don't have the intermediates, get them from your certificate provider's download page. Afterwards, use the SSL Certificate Checker to confirm the chain is complete.
What are the equivalent OpenSSL commands?
PEM to PFX: openssl pkcs12 -export -in cert.pem -inkey key.pem -certfile chain.pem -out cert.pfx PFX to PEM: openssl pkcs12 -in cert.pfx -nodes -out all.pem PEM to DER: openssl x509 -in cert.pem -outform der -out cert.der DER to PEM: openssl x509 -inform der -in cert.der -out cert.pem PEM to JKS: convert to PFX as above, then run keytool -importkeystore -srckeystore cert.pfx -srcstoretype PKCS12 -destkeystore cert.jks -deststoretype JKS OpenSSL 3 encrypts exported PFX files with AES by default, which Windows Server 2016 and earlier can't import; add -legacy to the export command. If reading a PFX exported by older Windows fails, add -legacy as well.

Converting formats after every renewal? Hand it to LapseZero

Certificates renew before they expire and get installed in the format your servers need — no more downloading, converting and uploading. Start on the free plan.

Start for free