如何将DigiCert提供的PRIVATE KEY转换为ENCRYPTED PRIVATE KEY?
Absolutely—you can convert your unencrypted PRIVATE KEY to the encrypted ENCRYPTED PRIVATE KEY format your application expects using OpenSSL's pkcs8 command. Here's exactly how to do it:
Step-by-Step Command
Run this in your terminal, adjusting filenames and the password to match your setup:
openssl pkcs8 -topk8 -inform PEM -in xyz_com.key -out encrypted_xyz_com.key -passout pass:abcde
Parameter Breakdown:
-topk8: Specifies we’re converting to the PKCS#8 format (this is the standard format for encrypted private keys, matching your original workingca_cert.key).-inform PEM: Tells OpenSSL your input key (xyz_com.key) uses PEM formatting (confirmed by its-----BEGIN PRIVATE KEY-----header).-in xyz_com.key: The path to your unencrypted private key file.-out encrypted_xyz_com.key: The path where your new encrypted key will be saved.-passout pass:abcde: Sets the encryption password toabcde—use the same password as your originalca_cert.keyto keep your application’s configuration consistent.
Verify the Result
After running the command, check the output file (encrypted_xyz_com.key). It should start with:
-----BEGIN ENCRYPTED PRIVATE KEY-----
This matches the header of your working ca_cert.key, so your application should now be able to use this encrypted key just like it did the self-signed one.
Optional: Interactive Password Input
If you don’t want to type your password in plaintext on the command line, replace -passout pass:abcde with -passout stdin. The command will then prompt you to enter the password after running it.
内容的提问来源于stack exchange,提问作者Manthan Tilva

