Inspect, Convert and Export Keys with openssl pkey
You will use openssl pkey to check a private key, derive a public-key file, inspect public components, and convert between PEM and DER. These are read or file-generation operations: they do not require a running service or root access. Allow about fifteen minutes, including time to check the output files.
The route
Jump straight to the step you need, or tick off Done means at the end.
The examples match the installed openssl-pkey(1ssl) manual for OpenSSL 3.0.13, provided by the Debian openssl package on this machine. The command found first in this shell may be another OpenSSL installation, so start by checking which binary and version you are actually using.
1. Confirm the command and prepare a test key
Run this as an ordinary user. The key is created under /tmp for practice and is not suitable for a real identity, certificate or service:
$ command -v openssl
/usr/bin/openssl
$ /usr/bin/openssl version
OpenSSL 3.0.13 30 Jan 2024 (Library: OpenSSL 3.0.13 30 Jan 2024)
$ workdir=$(mktemp -d /tmp/openssl-pkey-guide.XXXXXX)
$ /usr/bin/openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out "$workdir/private.pem"
Your version date can differ. If command -v points to a different installation, use its absolute path consistently, or use /usr/bin/openssl in the examples when you intend to exercise the packaged command. Keep the temporary directory private while it contains a private key.
Security checkpoint
A private key is a secret. Do not paste its contents into a ticket, chat or shell transcript. Do not use /tmp for a production key, and do not run the examples with sudo unless the real input directory genuinely requires it.
2. Check a private or public key
Use -check when the input contains a private key. It checks the consistency of the private and public components and writes a short result:
$ /usr/bin/openssl pkey -in "$workdir/private.pem" -check -noout
Key is valid
-noout suppresses the encoded key, leaving the diagnostic on standard output. A non-zero exit status means the command could not accept or validate the input. Capture it immediately if a script needs to distinguish success from failure:
if /usr/bin/openssl pkey -in "$workdir/private.pem" -check -noout; then
printf '%s\n' 'private key check passed'
else
status=$?
printf 'private key check failed: %s\n' "$status" >&2
exit "$status"
fi
For a public-key file, add -pubin and use -pubcheck. Without -pubin, pkey assumes private-key input by default.
3. Export only the public key
Many systems need the public half while the private half must remain protected. Create a new file with -pubout:
$ /usr/bin/openssl pkey -in "$workdir/private.pem" \
-pubout -out "$workdir/public.pem"
$ /usr/bin/openssl pkey -pubin -in "$workdir/public.pem" -pubcheck -noout
Key is valid
$ head -n 1 "$workdir/public.pem"
-----BEGIN PUBLIC KEY-----
The public file is PEM by default. The private input is not changed. The -pubout option restricts encoded output to public components, while -text_pub is useful when you need a readable inspection of those components instead of another PEM file:
$ /usr/bin/openssl pkey -in "$workdir/private.pem" -text_pub -noout | sed -n '1,3p'
Public-Key: (2048 bit)
Modulus:
...
The modulus and other values are key material, so redact them before sharing command output. The ellipsis above is only a display placeholder, not literal output.
4. Convert PEM to DER
PEM is a text encoding with boundary lines. DER is binary, so use -outform DER and a different output filename:
$ /usr/bin/openssl pkey -in "$workdir/private.pem" \
-outform DER -out "$workdir/private.der"
$ file "$workdir/private.pem" "$workdir/private.der"
/tmp/openssl-pkey-guide.XXXXXX/private.pem: PEM private key
/tmp/openssl-pkey-guide.XXXXXX/private.der: data
The exact file wording varies. The useful checks are a successful exit status, a non-empty destination and the expected format. To read DER again, specify the input format explicitly:
$ /usr/bin/openssl pkey -inform DER -in "$workdir/private.der" \
-check -noout
Key is valid
The manual defaults output to PEM, but input format is not something to guess when a file is known to be DER. Keep the source and destination names separate: the manual warns that the output filename should not be the same as the input filename.
5. Handle encrypted private keys deliberately
If the input key is encrypted and you omit -passin, OpenSSL prompts for its pass phrase. You can also provide a password source with -passin, but avoid putting real secrets directly in a command that may be saved in shell history or visible to other users. An interactive prompt is often the safer demonstration:
$ /usr/bin/openssl pkey -in /path/to/encrypted-key.pem \
-check -noout
Enter pass phrase for /path/to/encrypted-key.pem:
Key is valid
Adding a cipher option when writing PEM encrypts a private key, and OpenSSL prompts for the output pass phrase if -passout is absent. Encryption is not supported for DER output according to this manual. Do not remove encryption from a live private key until every consumer has been checked and a protected replacement is ready.
6. Avoid the common traps
- Public input rejected: retry with
-pubin. The default input interpretation is private key. - Unexpected PEM on standard output: add
-nooutwhen you only want text or a validation result. - Binary data in a terminal: do not combine DER output with a terminal destination. Give
-outa filename. - Overwriting a useful key: choose a new output path first, then validate it before any planned replacement. Shell redirection and
-outcan truncate an existing file. - EC-only options:
-ec_param_encand-ec_conv_formapply to elliptic-curve keys, not RSA keys. The documented parameter encodings arenamed_curveandexplicit. - Old engine instructions:
-engineis deprecated in OpenSSL 3.0. Follow your provider configuration instead of copying an old engine setup blindly.
If a command fails, preserve the original input and read the error without repeatedly changing formats. Check the path with ls -l, confirm whether the file is PEM or DER, and rerun a non-destructive check. There is no need for elevated privileges merely because the key is cryptographic.
Done means
- The binary and OpenSSL version were confirmed before the conversion.
- The input passed
-check, or a public input passed-pubcheckwith-pubin. - A separate public-key file was created with
-puboutwhere needed. - PEM and DER destinations were kept separate and read back with the correct format.
- Private-key contents and pass phrases stayed out of shared output, and the original file remains available for recovery.