Privacy-Enhanced Mail (.PEM)
wikipedia:Privacy-Enhanced Mail extension for X.509 certificates. .pem defined in RFCs 1421 through 1424, this is a container format that may include just the public certificate (such as with Apache installs, and CA certificate files /etc/ssl/certs/), or may include an entire certificate chain including public key, private key and root certificates. Confusingly, it may also encode a CSR (e.g. as used here) as the PKCS10 format can be translated into PEM. The name is from Privacy Enhanced Mail (PEM), a failed method for secure email but the container format it used lives on, and is a base64 translation of the x509 ASN.1 keys.[1]
ssh-keygen -m PEM -t rsa -f your_new_rsa_key.pem
Read certificate:
openssl x509 -in certificate.pem -textopenssl s_client -showcerts -connect YOUR_DOMAIN.COM:443keytool -printcert -file certificate.pem
Generate certificate:
PKCS7 chain in DER format. These files also may be named with a .p7b extension
- OpenSSH 7.8, (August 2018) Incompatible changes:
ssh-keygenwrite OpenSSH format private keys by default instead of using OpenSSL's PEM format.
file your_pem_file.pem your_pem_file.pem PEM RSA private key
file example.org.csr example.org.csr: PEM certificate request
file your_cert_for_development.cer your_cert_for_development.cer: Certificate, Version=3
Related terms[edit]
.cer.crt- X.509
ssh-keygen -mandopenssl req.crt(Core FTP).key(Core FTP)- Let's Encrypt:
certbot certonly,certbot certificates - Nginx
ssl_certificatedirective .pfxor.p12IdentityFile- PEM (RFC 1421)
- OpenSSH PEM (RFC 4716)
- tls_private_key
Activities[edit]
- Read about certificate extensions: https://knowledge.digicert.com/generalinformation/INFO2824.html
- Generate .p12 from .pem
See also[edit]
base64, base64 --decode, Serialized- Certificate:
.pem,.ppk,.pfx,.p12,.cer, .crt,openssl pkcs12,.csr,.pub, PFX, PKCS, PKCS, RFC 5280 - PEM, Certificate extensions,
ssh-keygen -m PEM, RFC 1421, OpenSSH PEM (RFC 4716) - Certificate, CSR (PKCS10),
/etc/letsencrypt/csr/,openssl req, X.509, [.pem,.cer,.csr], Kubernetes CertificateSigningRequest - X.509, ASN.1,
openssl x509,.pem, der, PFX, PKCS, SAN,openssl x509, CSR, Java KeyStore (JKS), Certificate Revocation List (CRL), Extended Key Usages (ECU), PKIX - Certificate, certificate extensions (
.pem,.pfx, .p8, .p12), CSR,.csr, root certificate, public certificate, Kubernetes certificate authentication - PKCS, PKCS7, PKCS8, PKCS10, PKCS12
Advertising: