PFX / PKCS#12 Generator
Package a certificate, matching private key and optional chain into a password-protected PFX/PKCS#12 file locally for Windows or IIS.
Privacy: all processing happens locally in your browser. Your input never leaves your device.
What is PFX / PKCS#12 Generator?
PFX (PKCS#12, commonly .pfx or .p12) packages a private key, leaf certificate and optional intermediate chain behind a passphrase, often for Windows certificate stores and IIS. Before packaging, the leaf certificate must match the private key and the chain must be correct. A PFX password protects the exported container; it does not make sharing safe. Anyone who obtains both the file and password can use the private key, so deliver them through separate controlled channels.
How to Use
- Import the leaf certificate, matching private key and optional intermediates
- Confirm the key match and choose a strong, separately stored PFX password
- Generate the local .pfx/.p12, import it into the target and validate its complete chain
FAQ
- Should a PFX always have a password?
- Yes. An unprotected PFX makes accidental private-key exposure easier; deliver the password separately from the file.
- Why does IIS still report an incomplete chain?
- The PFX may be missing intermediate certificates or have an incorrect chain. Use the exact CA-provided chain and check the target certificate path.
- Is PFX safer than PEM?
- Security depends on key protection, password, storage permissions and delivery. PFX is a convenient container, not a key-management system.
Related Tools
SSL Key Pair GeneratorGenerate RSA, ECC or SM2 PEM key pairs locally: RSA 2048/3072/4096 and P-256/P-384 are supported.Key Format ConverterConvert RSA PKCS#1 and general PKCS#8 private keys locally, optionally changing output password protection without changing the underlying key.Private Key Parameter ParserInspect public parameters of an RSA, ECC or SM2 private key and export its public key locally, without revealing private mathematical components.Public Key Parameter ParserParse the algorithm, RSA bit length or elliptic-curve parameters of an RSA, ECC or SM2 PEM/DER public key locally.CSR GeneratorCreate a local CSR and private key with DNS/IP SANs using RSA, ECC P-256/P-384 or SM2.CSR Parser & Signature CheckerParse a PEM/DER CSR, show subject, public key and DNS/IP SANs, and verify its embedded signature locally.
Last updated 2026-10-09