Home / Alt manpages / openssl-pkcs7(1ssl)

  • openssl-pkcs7(1ssl)
  • OpenSSL command
  • linux

Inspect and Convert PKCS#7 Files with OpenSSL pkcs7

You will finish with a repeatable way to identify a PKCS#7 file, convert it between PEM and DER, and extract the certificates it contains. The examples use OpenSSL 3.6.1, the version installed on this machine. Allow about ten minutes. You need a shell and a readable PKCS#7 file. None of the normal commands need sudo.

Checkpoint

This command reads and writes certificate containers. It does not verify a certificate chain, validate a signature or convert modern CMS input. Keep the original file until the converted copy has been checked.

1. Confirm the installed command

Check the binary and version before relying on option details. This is an ordinary, read-only check:

$ command -v openssl
/usr/bin/openssl
$ openssl version
OpenSSL 3.6.1 27 Jan 2026

The subcommand is openssl pkcs7. Its input and output format options are PEM and DER, and PEM is the default for both. If your package reports another major version, run openssl pkcs7 -help and review the local manual before putting the command into a script.

2. Inspect a PEM file without rewriting it

Give the input file explicitly and use -print with -noout to display the decoded PKCS#7 structure without emitting another encoded copy:

$ openssl pkcs7 -in bundle.pem -print -noout
PKCS7:
  type: pkcs7-signedData (1.2.840.113549.1.7.2)
  d.sign:
    version: 1
    ...

The details depend on the file. The useful check is that the command exits successfully and prints a PKCS#7 object rather than an input-format error. -print is diagnostic output, while -noout suppresses the normal encoded output. Without -noout, OpenSSL can print the structure and then write the input object again, which is often confusing when the output is your terminal.

If you omit -in, the command reads standard input. If you omit -out, encoded output goes to standard output. Those defaults are convenient for pipelines, but make the destination explicit when a file is valuable.

3. Extract the certificates

Use -print_certs when you want the certificates or CRLs held in the PKCS#7 structure rather than the wrapper itself:

$ openssl pkcs7 -in bundle.pem -print_certs -out certs.pem
$ sed -n '1,4p' certs.pem
subject=CN=pkcs7-guide-test
issuer=CN=pkcs7-guide-test
-----BEGIN CERTIFICATE-----

The subject and issuer lines are added by this command. The certificate blocks follow in PEM format. The exact distinguished names will differ for your file. Check the result before replacing any existing certificate file:

$ openssl x509 -in certs.pem -noout -subject -issuer
subject=CN=pkcs7-guide-test
issuer=CN=pkcs7-guide-test

That check assumes the extracted file contains one certificate. For a bundle, split or process the PEM blocks with a certificate-aware tool rather than treating the whole file as one certificate.

For scripts that need only PEM blocks, add -quiet to -print_certs:

$ openssl pkcs7 -in bundle.pem -print_certs -quiet -out certs-only.pem
$ sed -n '1p' certs-only.pem
-----BEGIN CERTIFICATE-----

-quiet only changes the extra subject and issuer lines. It does not make an untrusted certificate trusted, and it does not perform chain verification.

4. Convert PEM to DER safely

Set -outform DER and name a new destination. The input remains PEM because -inform is omitted:

$ openssl pkcs7 -in bundle.pem -outform DER -out bundle.der
$ file bundle.pem bundle.der
bundle.pem: ASCII text
bundle.der: DER Encoded PKCS#7 Signed Data

To convert back, make both formats explicit:

$ openssl pkcs7 -inform DER -in bundle.der -outform PEM -out bundle-roundtrip.pem
$ openssl pkcs7 -in bundle-roundtrip.pem -print -noout | sed -n '1,5p'
PKCS7:
  type: pkcs7-signedData (1.2.840.113549.1.7.2)
  d.sign:

Format conversion is not validation of the certificates or their signatures. Compare the decoded contents, fingerprints or application-level result when identity matters.

Safety warning

Shell redirection and -out can overwrite a useful file. Write to a new name such as bundle.der.new, inspect it, then replace the old file deliberately. If a failed run leaves an incomplete new file, remove that new file only after confirming the original was not targeted. Do not delete the original as part of a blind batch.

5. Diagnose the two common format mistakes

An input-format error often means that the file is DER while the command assumed PEM, or the reverse. Retry with the other -inform value:

$ openssl pkcs7 -inform DER -in bundle.der -print -noout
PKCS7:
  type: pkcs7-signedData (1.2.840.113549.1.7.2)
  ...

Do not infer the format from the filename extension alone. A PEM file is text with header and footer lines; DER is binary. Use file as a clue, then confirm by successfully parsing the object.

OpenSSL 3.6.1's pkcs7 command understands PKCS#7 version 1.5 as defined by RFC 2315. It does not parse CMS as defined by RFC 2630. If the file is CMS, use a CMS-aware command such as openssl cms where its operation matches your requirement. Do not force a CMS file through pkcs7 and treat an error as a certificate problem.

Done means

  • You confirmed the installed OpenSSL version and checked the local option set.
  • You inspected the PKCS#7 wrapper with -print -noout.
  • You extracted certificates with -print_certs, using -quiet only when the extra labels were unwanted.
  • You converted between PEM and DER with the correct -inform and -outform values.
  • You kept the original file and distinguished format conversion from certificate verification.
  • You recognised that this command handles PKCS#7 v1.5, not CMS.