Export and inspect PKCS#12 files with OpenSSL
You will create a password-protected PKCS#12 file, inspect its algorithms without printing credentials, and extract either the client certificate or private key as PEM. The examples use OpenSSL 3.6.1, installed here on Linux. Allow about fifteen minutes if you already have a PEM certificate and matching key.
The route
Jump straight to the step you need, or tick off Done means at the end.
PKCS#12 files are commonly named .p12 or .pfx. They can contain a private key, its certificate and additional CA certificates. The same command parses a PKCS#12 file by default; add -export when creating one.
1. Check the installed command
These are ordinary, read-only checks and do not need elevated privileges:
$ command -v openssl
/usr/bin/openssl
$ openssl version
OpenSSL 3.6.1 27 Jan 2026
Your version and path may differ. This guide follows the installed OpenSSL 3.6.1 manual. In OpenSSL 3, -noenc is the current spelling for leaving an extracted private key unencrypted; -nodes is deprecated.
Checkpoint: have a PEM file containing one private key and its matching certificate, or keep them as separate files. Do not paste a private key into a shell command or store it in a world-readable directory.
2. Export a protected PKCS#12 file
With separate certificate and key files, create the bundle like this:
$ openssl pkcs12 -export \
-in /path/to/certificate.pem \
-inkey /path/to/private-key.pem \
-out /path/to/client-identity.p12 \
-name 'Client identity'
OpenSSL prompts for an export password. Use a strong password and pass it through your normal password manager. The resulting file contains the private key, so treat it as sensitive and restrict its permissions:
$ chmod 600 /path/to/client-identity.p12
$ stat -c '%A %n' /path/to/client-identity.p12
-rw------- /path/to/client-identity.p12
In OpenSSL 3.6.1, the default certificate and private-key encryption is AES-256-CBC with PBKDF2. The export also uses a SHA-256 MAC and an iteration count of 2048 by default. These defaults are visible with the inspection step below, so do not infer them from the file extension.
Warning: -out replaces an existing destination. Use a new name first, or make a backup before an intentional replacement. If the export fails, keep the original files and remove only the incomplete new file.
3. Inspect the container without outputting credentials
Use -info with -noout to display the structure, algorithms and iteration counts while suppressing certificate and key output:
$ openssl pkcs12 -in /path/to/client-identity.p12 -info -noout
Enter Import Password:
MAC: sha256, Iteration 2048
MAC length: 32, salt length: 16
PKCS7 Encrypted data: PBES2, PBKDF2, AES-256-CBC, Iteration 2048, PRF hmacWithSHA256
Certificate bag
PKCS7 Data
Shrouded Keybag: PBES2, PBKDF2, AES-256-CBC, Iteration 2048, PRF hmacWithSHA256
The exact bag order and wording can vary with the file. The useful checks are a successful exit status, a verified MAC and encryption that matches the software receiving the file. -noout does not decrypt nothing: OpenSSL still reads and verifies the container, but does not write its credentials to standard output.
Checkpoint: if this reports Mac verify error: invalid password?, stop and check the password before changing any options. A wrong password and a damaged file can produce similar symptoms.
4. Extract only the client certificate
Parsing writes PEM to standard output by default. Select the end-entity certificate and suppress the private key with -clcerts -nokeys:
$ openssl pkcs12 \
-in /path/to/client-identity.p12 \
-clcerts -nokeys \
-out /path/to/client-certificate.pem
Enter Import Password:
$ openssl x509 -in /path/to/client-certificate.pem -noout -subject -issuer
subject=CN=client.example
issuer=CN=Example Issuing CA
-clcerts excludes CA certificates. If you need only the CA certificates, use -cacerts -nokeys instead. Without one of these filters, OpenSSL writes all certificates in the order stored in the container; that order is not guaranteed to put the certificate matching the private key first.
Do not add -noenc to this certificate-only extraction. It affects private keys, not certificates, and the certificate is not secret in the same way as the private key.
5. Extract a private key only when the next tool requires it
Some programs require a separate PEM key. Extract it without a certificate:
$ openssl pkcs12 \
-in /path/to/client-identity.p12 \
-nocerts \
-out /path/to/private-key-encrypted.pem
Enter Import Password:
Enter PEM pass phrase:
Verifying - Enter PEM pass phrase:
The extracted PEM key is encrypted with a second passphrase. Keep it protected:
$ chmod 600 /path/to/private-key-encrypted.pem
$ openssl pkey -in /path/to/private-key-encrypted.pem -noout
Enter pass phrase for /path/to/private-key-encrypted.pem:
Only use the unencrypted form when the receiving program cannot read an encrypted PEM key and its storage is controlled:
$ openssl pkcs12 \
-in /path/to/client-identity.p12 \
-nocerts -noenc \
-out /path/to/private-key.pem
Enter Import Password:
$ chmod 600 /path/to/private-key.pem
This writes a plaintext private key to disk. Warning: it is a security-sensitive change. Delete it as soon as the consuming program has imported it, following that program's documented recovery procedure. If you need to undo the extraction, remove only the generated key after confirming that the original PKCS#12 file is still available and usable. Do not delete the original bundle as a shortcut.
6. Handle older PKCS#12 files
OpenSSL 3 does not load its legacy provider by default. An older file using algorithms such as RC2-40-CBC may therefore fail before the password is accepted. Try legacy mode only when the file is known to be old or a trusted application identifies a legacy algorithm:
$ openssl pkcs12 -in /path/to/old-client.p12 -info -noout -legacy
Enter Import Password:
Legacy mode changes the algorithms OpenSSL will load; it does not convert the file. After a successful read, export a replacement with current defaults and test that replacement in the receiving application:
$ openssl pkcs12 -legacy \
-in /path/to/old-client.p12 \
-out /tmp/old-client.pem
Enter Import Password:
$ openssl pkcs12 -export \
-in /tmp/old-client.pem \
-out /path/to/new-client.p12
Enter Export Password:
Verifying - Enter Export Password:
The temporary PEM includes credentials. Use a private temporary directory, restrict its permissions, and remove it after testing. If OpenSSL is not installed system-wide, legacy mode may also need -provider-path or the OPENSSL_MODULES environment variable pointing at the provider directory. Do not guess that path; obtain it from the installation.
Common traps
- Putting a password in the command line: avoid
-passin pass:...and-passout pass:...for normal use because shell history and process inspection can expose the value. Interactive prompts are safer for a manual operation. OpenSSL also supports other password sources documented byopenssl-passphrase-options. - Using
-twopasscasually: it creates separate integrity and encryption passwords, and many applications assume they are the same. Such a file may be unreadable by otherwise compatible software. - Running as root: these commands normally need no elevated privileges. Fix ownership or directory permissions rather than using
sudoaround a private-key export. - Assuming a successful parse proves the right identity: check the certificate subject, issuer and, where relevant, fingerprint before handing the extracted files to another service.
Done means
- The PKCS#12 file was exported with a password and has mode
600where appropriate. -info -nooutverified the password and showed the container algorithms without printing credentials.- The required certificate or key was extracted with the correct filter.
- Any plaintext private key was deliberate, access-controlled and removed after use.
- Legacy mode was used only for a known compatibility case, followed by a tested re-export where possible.