Key Format Converter
Convert RSA PKCS#1 and general PKCS#8 private keys locally, optionally changing output password protection without changing the underlying key.
Privacy: all processing happens locally in your browser. Your input never leaves your device.
What is Key Format Converter?
RSA private keys can use PKCS#1 or PKCS#8, while EC and SM2 private keys can use general PKCS#8. A service that cannot read a private key may require a different container. This tool converts private-key containers without changing the mathematical key. PKCS#1 output is available only for RSA. Convert only to meet a confirmed target requirement; conversion is not key rotation and a private key must never be shared as if it were public.
How to Use
- Paste the PEM key and enter its password locally if needed
- Choose PKCS#8 or RSA-only PKCS#1, optionally setting an output protection password
- Check the PEM boundary and algorithm, then copy or download the result
FAQ
- What is the difference between PKCS#1 and PKCS#8?
- PKCS#1 is an RSA-specific private-key encoding. PKCS#8 is a general private-key container for RSA, EC, SM2 and other algorithms.
- Does conversion make a new key?
- No. It changes encoding only; the corresponding public key and fingerprint should remain the same.
- Why does an encrypted key need a password?
- The password decrypts the protected PEM locally. Wrong passwords or unsupported protection are rejected rather than bypassed.
Related Tools
SSL Key Pair GeneratorGenerate RSA, ECC or SM2 PEM key pairs locally: RSA 2048/3072/4096 and P-256/P-384 are supported.Private Key Parameter ParserInspect public parameters of an RSA, ECC or SM2 private key and export its public key locally, without revealing private mathematical components.Public Key Parameter ParserParse the algorithm, RSA bit length or elliptic-curve parameters of an RSA, ECC or SM2 PEM/DER public key locally.CSR GeneratorCreate a local CSR and private key with DNS/IP SANs using RSA, ECC P-256/P-384 or SM2.CSR Parser & Signature CheckerParse a PEM/DER CSR, show subject, public key and DNS/IP SANs, and verify its embedded signature locally.Self-Signed SSL Certificate GeneratorGenerate local self-signed TLS certificates with DNS/IP SANs for development, intranets and controlled testing using RSA, ECC or SM2.
Last updated 2026-10-09