Solved

Generate PKCS12 file from .cer and .pvk

Posted on 2014-01-20
6
2,083 Views
Last Modified: 2014-01-20
Hi Experts,

How can I generate a pfx file from a .cer and .pvk file?

Thanks,
Mike
0
Comment
Question by:thready
  • 3
  • 2
6 Comments
 
LVL 8

Expert Comment

by:amatson78
Comment Utility
You can use openssl:

# openssl pkcs12 -export -out certificate.pfx -inkey certificate.key -in certificate.crt

If you need to include the certificate chain you can add "-certfile CACert.crt"

# openssl pkcs12 -export -out certificate.pfx -inkey certificate.key -in certificate.crt -certfile CACert.crt

You will be prompted to create a password twice and then cert should be created. You can check the cert with:

#openssl pkcs12 -info -in certificate.pfx
0
 
LVL 1

Author Comment

by:thready
Comment Utility
My key is in the Microsoft proprietary blob format (.PVK) - not any of the formats required by OpenSSL...
0
 
LVL 8

Accepted Solution

by:
amatson78 earned 400 total points
Comment Utility
My apoligies I missed that part. I should have read better. Since you have the .pvk already that part should be good. First convert the .cer to a .spc with Cert2spc.exe (http://msdn.microsoft.com/en-us/library/f657tk8f(v=vs.110).aspx):

cert2Spc.exe certificate.cer certificate.spc

Open in new window


Then once that is done use pvk2pfx (http://msdn.microsoft.com/en-us/library/windows/hardware/ff550672(v=vs.85).aspx) to merge the .spc and the .pvk to a .pfx file:

pvk2pfx.exe -pvk yourkey.pvk -pi <password> -spc certificate.spc -pfx certificate.pfx -po <password>

Open in new window


See if that works for you.

Cheers, Alan
0
How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

 
LVL 33

Assisted Solution

by:Dave Howe
Dave Howe earned 100 total points
Comment Utility
you can download a conversion tool to standard PEM format here:

http://www.drh-consultancy.demon.co.uk/pvk.html

once it is in PEM format, you can use openssl or any other suitable tool (I prefer XCA) to convert that and the CER into the #12 format.
0
 
LVL 1

Author Closing Comment

by:thready
Comment Utility
Thank you!
0
 
LVL 8

Expert Comment

by:amatson78
Comment Utility
Glad that it helped and thank you for the Awesome rating :)

Cheers, Alan
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Microservice architecture adoption brings many advantages, but can add intricacy. Selecting the right orchestration tool is most important for business specific needs.
If you get continual lockouts after changing your Active Directory password, there are several possible reasons.  Two of the most common are using other devices to access your email and stored passwords in the credential manager of windows.
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now