无私钥情况下将DER格式CSR转换为PEM格式的方法
Short Answer: Yes, this is totally feasible!
DER and PEM are just two different encoding formats for the exact same CSR data. The private key was only used to sign the CSR when it was created, but you don’t need it to convert the file’s encoding—since the CSR itself only contains public information (your public key, subject details, and the signature, which doesn’t require the private key to decode).
Step-by-Step Conversion with OpenSSL
You can use the standard openssl tool (preinstalled on Linux/macOS; available for Windows via WSL or official binaries) to do the conversion in one command:
openssl req -inform DER -in your_okta_csr.der -outform PEM -out converted_csr.pem
Let’s break down what each part does:
-inform DER: Tells OpenSSL your input file uses the binary DER format-in your_okta_csr.der: Replace this with the actual filename of your Okta-provided DER CSR-outform PEM: Sets the output to use PEM’s base64-encoded text format-out converted_csr.pem: The name of the PEM file you want to generate
Verify the Conversion Worked
To make sure the PEM file is valid and contains the correct data, run this command to print human-readable details of the CSR:
openssl req -in converted_csr.pem -text -noout
You’ll see things like the CSR’s subject (organization name, common name, etc.), public key specifications, and signature algorithm—clear signs the conversion went smoothly.
内容的提问来源于stack exchange,提问作者tcotts

