OmniConvert

PEM vs DER: Certificate File Formats (PEM, DER, CER, CRT) Explained

X.509 certificates, the files behind HTTPS, code signing and client authentication, are stored in one of two encodings: DER, which is binary, or PEM, which is the same data Base64-encoded as text. The certificate itself is identical; only the way it is written to disk differs.

File extensions add to the confusion: .pem and .der describe the encoding, but .cer and .crt are used for both.

Example: The beginning of a PEM certificate (Let's Encrypt ISRG Root X1), shortened
-----BEGIN CERTIFICATE-----
MIIFazCCA1OgAwIBAgIRAIIQz7DSQONZRGPgu2OCiwAwDQYJKoZIhvcNAQELBQAw
TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh
cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMTUwNjA0MTEwNDM4
…
-----END CERTIFICATE-----

Convert PEM / DER / CER / CRT files

DER: the binary encoding

Certificates are defined in ASN.1, and DER (Distinguished Encoding Rules) is its compact binary serialization. A DER file holds exactly one object, such as one certificate, and looks like random bytes in a text editor. Java tools and Windows often use DER.

PEM: the text encoding

PEM is the DER bytes Base64-encoded, split into 64-character lines and wrapped in -----BEGIN …----- and -----END …----- markers (the name comes from the 1990s "Privacy-Enhanced Mail" standard). Because it is text, a PEM file can be pasted into emails and config files and can hold several objects, such as a full certificate chain. Apache, Nginx, OpenSSL and most Linux software expect PEM.

The marker says what the block contains: CERTIFICATE, CERTIFICATE REQUEST (a CSR), PUBLIC KEY, or PRIVATE KEY / RSA PRIVATE KEY.

What do .cer, .crt, .pem and .der mean?

  • .pem: PEM text; can contain certificates, chains or keys
  • .der: binary DER
  • .crt: a certificate in either encoding; on Linux and with Apache/Nginx it is usually PEM
  • .cer: a certificate in either encoding; Windows exports it as "DER encoded binary X.509" or "Base-64 encoded X.509"
  • .key: a private key, usually PEM. Never share or upload it
  • .p7b / .p7c: a PKCS#7 bundle of certificates without a private key
  • .pfx / .p12: a PKCS#12 archive with certificate and private key, protected by a password

How to tell PEM from DER

Open the file in a text editor. If it starts with -----BEGIN CERTIFICATE-----, it is PEM; if it shows unreadable characters, it is DER. With OpenSSL, openssl x509 -in file.cer -noout -text reads PEM, and adding -inform der reads DER.

Converting with OpenSSL

# DER (.der/.cer/.crt) to PEM
openssl x509 -inform der -in certificate.cer -out certificate.pem

# PEM to DER
openssl x509 -outform der -in certificate.pem -out certificate.der

Frequently Asked Questions

What is the difference between PEM and DER?
Only the encoding. DER is the certificate in binary form; PEM is the same bytes Base64-encoded as text between BEGIN/END markers. Converting between them is lossless.
Is a .cer file PEM or DER?
It can be either. Open it in a text editor: text starting with -----BEGIN CERTIFICATE----- is PEM, unreadable binary is DER.
Is it safe to convert a certificate online?
Certificates are public by design: every HTTPS server sends its certificate to every visitor. Private keys are different. Never upload a .key, .pfx or .p12 file, or any PEM block marked PRIVATE KEY, to an online tool.

More format guides