PFX / PKCS#12 Generator

Package a certificate, matching private key and optional chain into a password-protected PFX/PKCS#12 file locally for Windows or IIS.

Privacy: all processing happens locally in your browser. Your input never leaves your device.

What is PFX / PKCS#12 Generator?

PFX (PKCS#12, commonly .pfx or .p12) packages a private key, leaf certificate and optional intermediate chain behind a passphrase, often for Windows certificate stores and IIS. Before packaging, the leaf certificate must match the private key and the chain must be correct. A PFX password protects the exported container; it does not make sharing safe. Anyone who obtains both the file and password can use the private key, so deliver them through separate controlled channels.

How to Use

  1. Import the leaf certificate, matching private key and optional intermediates
  2. Confirm the key match and choose a strong, separately stored PFX password
  3. Generate the local .pfx/.p12, import it into the target and validate its complete chain

FAQ

Should a PFX always have a password?
Yes. An unprotected PFX makes accidental private-key exposure easier; deliver the password separately from the file.
Why does IIS still report an incomplete chain?
The PFX may be missing intermediate certificates or have an incorrect chain. Use the exact CA-provided chain and check the target certificate path.
Is PFX safer than PEM?
Security depends on key protection, password, storage permissions and delivery. PFX is a convenient container, not a key-management system.

Related Tools

Last updated 2026-10-09