PEM vs DER: Certificate File Formats (PEM, DER, CER, CRT) Explained
X.509 certificates, the files behind HTTPS, code signing and client authentication, are stored in one of two encodings: DER, which is binary, or PEM, which is the same data Base64-encoded as text. The certificate itself is identical; only the way it is written to disk differs.
File extensions add to the confusion: .pem and .der describe the encoding, but .cer and .crt are used for both.
-----BEGIN CERTIFICATE-----
MIIFazCCA1OgAwIBAgIRAIIQz7DSQONZRGPgu2OCiwAwDQYJKoZIhvcNAQELBQAw
TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh
cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMTUwNjA0MTEwNDM4
…
-----END CERTIFICATE-----Convert PEM / DER / CER / CRT files
- Convert CER to PEM— Convert a .cer certificate (DER or PEM encoded) to a PEM file
- Convert CRT to PEM— Convert a .crt certificate (DER or PEM encoded) to a PEM file
- Convert DER to PEM— Convert a binary DER certificate to base64-encoded PEM format
- Convert PEM to DER— Convert a PEM certificate or key to binary DER format
- Convert X.509 certificate to JSON— Decode an X.509 certificate (PEM or DER) and extract fields as JSON
- Convert CSR to JSON— Decode a PEM certificate signing request (CSR) and extract subject and metadata as JSON
DER: the binary encoding
Certificates are defined in ASN.1, and DER (Distinguished Encoding Rules) is its compact binary serialization. A DER file holds exactly one object, such as one certificate, and looks like random bytes in a text editor. Java tools and Windows often use DER.
PEM: the text encoding
PEM is the DER bytes Base64-encoded, split into 64-character lines and wrapped in -----BEGIN …----- and -----END …----- markers (the name comes from the 1990s "Privacy-Enhanced Mail" standard). Because it is text, a PEM file can be pasted into emails and config files and can hold several objects, such as a full certificate chain. Apache, Nginx, OpenSSL and most Linux software expect PEM.
The marker says what the block contains: CERTIFICATE, CERTIFICATE REQUEST (a CSR), PUBLIC KEY, or PRIVATE KEY / RSA PRIVATE KEY.
What do .cer, .crt, .pem and .der mean?
- .pem: PEM text; can contain certificates, chains or keys
- .der: binary DER
- .crt: a certificate in either encoding; on Linux and with Apache/Nginx it is usually PEM
- .cer: a certificate in either encoding; Windows exports it as "DER encoded binary X.509" or "Base-64 encoded X.509"
- .key: a private key, usually PEM. Never share or upload it
- .p7b / .p7c: a PKCS#7 bundle of certificates without a private key
- .pfx / .p12: a PKCS#12 archive with certificate and private key, protected by a password
How to tell PEM from DER
Open the file in a text editor. If it starts with -----BEGIN CERTIFICATE-----, it is PEM; if it shows unreadable characters, it is DER. With OpenSSL, openssl x509 -in file.cer -noout -text reads PEM, and adding -inform der reads DER.
Converting with OpenSSL
# DER (.der/.cer/.crt) to PEM
openssl x509 -inform der -in certificate.cer -out certificate.pem
# PEM to DER
openssl x509 -outform der -in certificate.pem -out certificate.derFrequently Asked Questions
- What is the difference between PEM and DER?
- Only the encoding. DER is the certificate in binary form; PEM is the same bytes Base64-encoded as text between BEGIN/END markers. Converting between them is lossless.
- Is a .cer file PEM or DER?
- It can be either. Open it in a text editor: text starting with -----BEGIN CERTIFICATE----- is PEM, unreadable binary is DER.
- Is it safe to convert a certificate online?
- Certificates are public by design: every HTTPS server sends its certificate to every visitor. Private keys are different. Never upload a .key, .pfx or .p12 file, or any PEM block marked PRIVATE KEY, to an online tool.