Apache本地自签名SSL证书:文件对应与重命名/转换疑问
Great question—file naming conventions for SSL artifacts can be tricky, but let’s break this down simply:
Are the files equivalent?
Yes, in almost all cases when you’re working with OpenSSL-generated self-signed certificates, these pairs are identical in content—only the file extensions differ:
- server.crt ↔ cert.pem: Both are SSL certificate files.
.crtis a common shorthand for "certificate", while.pemrefers to the PEM format (Base64-encoded text with standard-----BEGIN CERTIFICATE-----/-----END CERTIFICATE-----headers). OpenSSL generates self-signed certificates in PEM format by default, so these are interchangeable. - server.csr ↔ csr.pem: Both are Certificate Signing Request files.
.csris the direct abbreviation for "Certificate Signing Request", and.pemagain denotes the PEM format. Your OpenSSL-generated CSR will be in PEM format, so these are the same file with different names. - server.key ↔ key.pem: Both are RSA private key files.
.keyis a generic extension for cryptographic keys, and.pemindicates the PEM-encoded format (look for-----BEGIN RSA PRIVATE KEY-----or-----BEGIN PRIVATE KEY-----headers). OpenSSL’s default private key output is PEM, so these are identical.
Can you just rename them, or do you need conversion?
You can directly rename these files without any conversion—the file extension doesn’t determine the format; the content does. As long as the files are in PEM format (which they are if you used standard OpenSSL commands to generate them), renaming server.crt to cert.pem, server.csr to csr.pem, or server.key to key.pem will work perfectly with any tool or server that expects PEM-formatted files (like Nginx, Apache, or OpenSSL itself).
Quick way to verify format (optional)
If you want to double-check that your files are indeed PEM-formatted, run these OpenSSL commands:
- Check certificate:
openssl x509 -in server.crt -text -noout - Check CSR:
openssl req -in server.csr -text -noout - Check private key:
openssl rsa -in server.key -check -noout
If these commands output valid, human-readable details about the certificate/CSR/key, you’re good to go with renaming.
内容的提问来源于stack exchange,提问作者Daniel Dalan

