How to create a .pem file for SSL Certificate Installations | Support (2024)

This document (7013103) is provided subject to the disclaimer at the end of this document.

Environment

SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server 15

Situation

How to create a .pem file for SSL Certificate Installations

Resolution

Privacy Enhanced Mail (PEM) files are concatenated certificate containers frequently used in certificate installations when multiple certificates that form a complete chain are being imported as a single file. They are a defined standard in RFCs 1421 through 1424. They can be thought of as a layered container of chained certificates. A .pem file is a container format that may just include the public certificate or the entire certificate chain (private key, public key, root certificates):

  • Private Key
  • Server Certificate (crt, puplic key)
  • (optional) Intermediate CA and/or bundles if signed by a 3rd party

How to create a self-signed PEM file

openssl req -newkey rsa:2048 -new -nodes -x509 -days 3650 -keyout key.pem -out cert.pem

How to create a PEM file from existing certificate files that form a chain

  • (optional) Remove the password from the Private Key by following the steps listed below:
    openssl rsa -in server.key -out nopassword.key
    Note: Enter the pass phrase of the Private Key.
  • Combine the private key, public certificate and any 3rd party intermediate certificate files:
    cat nopassword.key > server.pemcat server.crt >> server.pem
    Note: Repeat this step as needed for third-party certificate chain files, bundles, etc:
    cat intermediate.crt >> server.pem

Additional Information

How to create a PEM file with the help of an automated script:

  • Download NetIQ Cool Tool OpenSSL-Toolkit.
  • Select Create Certificates | PEM with key and entire trust chain
  • Provide the full path to the directory containing the certificate files.
  • Provide the filenames of the following:
    • private key
    • public key (server crt)
    • (conditional) password for private key
    • (conditional) any intermediate certificate chain file(s)

For additional information, please see TID 7015502 - Common Mistakes in SSL Certificate Management & Implementation.

The following details the structure of a typical .pem file (including the entire certificate chain):

-----BEGIN RSA PRIVATE KEY----- (Private Key: domain_name.key contents) -----END RSA PRIVATE KEY----------BEGIN CERTIFICATE----- (Primary SSL certificate: domain_name.crt contents) -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- (Intermediate certificate: certChainCA.crt contents) -----END CERTIFICATE----

Disclaimer

This Support Knowledgebase provides a valuable tool for SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.

  • Document ID:7013103
  • Creation Date: 26-Aug-2013
  • Modified Date:11-Aug-2022
    • SUSE Linux Enterprise Server

< Back to Support Search

For questions or concerns with the SUSE Knowledgebase please contact: tidfeedback[at]suse.com

How to create a .pem file for SSL Certificate Installations | Support (2024)
Top Articles
VA.gov | Veterans Affairs
The Essential Guide on How to Use Hydra to Crack Passwords
NYT Mini Crossword today: puzzle answers for Tuesday, September 17 | Digital Trends
Koopa Wrapper 1 Point 0
Palm Coast Permits Online
Erika Kullberg Wikipedia
³µ¿Â«»ÍÀÇ Ã¢½ÃÀÚ À̸¸±¸ ¸íÀÎ, ¹Ì±¹ Ķ¸®Æ÷´Ï¾Æ ÁøÃâ - ¿ù°£ÆÄ¿öÄÚ¸®¾Æ
Wmu Course Offerings
Chelsea player who left on a free is now worth more than Palmer & Caicedo
Mcoc Immunity Chart July 2022
Mawal Gameroom Download
WK Kellogg Co (KLG) Dividends
Hover Racer Drive Watchdocumentaries
Jet Ski Rental Conneaut Lake Pa
Clairememory Scam
Orlando Arrest and Public Records | Florida.StateRecords.org
California Department of Public Health
Local Collector Buying Old Motorcycles Z1 KZ900 KZ 900 KZ1000 Kawasaki - wanted - by dealer - sale - craigslist
Magicseaweed Capitola
[Birthday Column] Celebrating Sarada's Birthday on 3/31! Looking Back on the Successor to the Uchiha Legacy Who Dreams of Becoming Hokage! | NARUTO OFFICIAL SITE (NARUTO & BORUTO)
Theresa Alone Gofundme
History of Osceola County
Committees Of Correspondence | Encyclopedia.com
Craigslist Portland Oregon Motorcycles
The Menu Showtimes Near Regal Edwards Ontario Mountain Village
Forum Phun Extra
Vigoro Mulch Safe For Dogs
Rufus Benton "Bent" Moulds Jr. Obituary 2024 - Webb & Stephens Funeral Homes
12 Top-Rated Things to Do in Muskegon, MI
How do you get noble pursuit?
Jamielizzz Leaked
Kelley Fliehler Wikipedia
Franklin Villafuerte Osorio
Redding Activity Partners
Inmate Search Disclaimer – Sheriff
Nextdoor Myvidster
P3P Orthrus With Dodge Slash
Deleted app while troubleshooting recent outage, can I get my devices back?
404-459-1280
Giantess Feet Deviantart
Pill 44615 Orange
Craigs List Stockton
Michael Jordan: A timeline of the NBA legend
Nancy Pazelt Obituary
Orion Nebula: Facts about Earth’s nearest stellar nursery
This 85-year-old mom co-signed her daughter's student loan years ago. Now she fears the lender may take her house
Rush Copley Swim Lessons
Gon Deer Forum
The Blackening Showtimes Near Ncg Cinema - Grand Blanc Trillium
Oak Hill, Blue Owl Lead Record Finastra Private Credit Loan
Concentrix + Webhelp devient Concentrix
Latest Posts
Article information

Author: Greg Kuvalis

Last Updated:

Views: 5400

Rating: 4.4 / 5 (55 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Greg Kuvalis

Birthday: 1996-12-20

Address: 53157 Trantow Inlet, Townemouth, FL 92564-0267

Phone: +68218650356656

Job: IT Representative

Hobby: Knitting, Amateur radio, Skiing, Running, Mountain biking, Slacklining, Electronics

Introduction: My name is Greg Kuvalis, I am a witty, spotless, beautiful, charming, delightful, thankful, beautiful person who loves writing and wants to share my knowledge and understanding with you.