Create a .pem File for TLS/SSL Certificate Installations
.pem TLS/SSL Creation Instructions
SSL .pem files (concatenated certificate container files), are frequently required for certificate installations when multiple certificates are being imported as one file.
This article contains multiple sets of instructions that walk through various .pem file creation scenarios for certificate installation.
- Create a .pem file with the Entire TLS/SSL Certificate Trust Chain
- Create a .pem file with the TLS/SSL Server and Intermediate Certificates
- Create a .pem with the Private Key and Entire Trust Chain
Create a .pem file with the Entire TLS/SSL Certificate Trust Chain
- In your CertCentral account, on the certificate's order details page, download your Intermediate (DigiCertCA.crt), Root (TrustedRoot.crt), and Primary Certificates (your_domain_name.crt).
See Download a TLS/SSL certificate from your CertCentral account - Open a text editor (such as Notepad) and paste the entire body of each certificate into one text file in the following order:
- Primary Certificate - your_domain_name.crt
- Intermediate Certificate - DigiCertCA.crt
- Root Certificate - TrustedRoot.crt
Note: Some servers may require you to add the certificates in the reverse order in the .pem file:
- Root Certificate
- Intermediate Certificate
- Primary Certificate
- Make sure to include the beginning and end tags on each certificate. The result should look like this:
-----BEGIN CERTIFICATE-----
Your Primary TLS/SSL certificate: your_domain_name.crt
-----END CERTIFICATE----------BEGIN CERTIFICATE-----
Your Intermediate certificate: DigiCertCA.crt
-----END CERTIFICATE----------BEGIN CERTIFICATE-----
Your Root certificate: TrustedRoot.crt
-----END CERTIFICATE----- - Save the combined file as your_domain_name.pem.
The .pem file is now ready to use.
Create a .pem file with the TLS/SSL Server and Intermediate Certificates
- In your CertCentral account, on the certificate's order details page, download your Intermediate (DigiCertCA.crt) and Primary Certificates (your_domain_name.crt).
See Download a TLS/SSL certificate from your CertCentral account - Open a text editor (such as Notepad) and paste the entire body of each certificate into one text file in the following order:
- The Primary Certificate - your_domain_name.crt
- The Intermediate Certificate - DigiCertCA.crt
- Make sure to include the beginning and end tags on each certificate. The result should look like this:
-----BEGIN CERTIFICATE-----
Your Primary TLS/SSL certificate: your_domain_name.crt
-----END CERTIFICATE----------BEGIN CERTIFICATE-----
Your Intermediate certificate: DigiCertCA.crt
-----END CERTIFICATE----- - Save the combined file as your_domain_name.pem.
The .pem file is now ready to use.
Create a .pem with the Private Key and Entire Trust Chain
- In your CertCentral account, on the certificate's order details page, download your Intermediate (DigiCertCA.crt), Root (TrustedRoot.crt), and Primary Certificates (your_domain_name.crt).
See Download a TLS/SSL certificate from your CertCentral account - Open a text editor (such as Notepad) and paste the entire body of each certificate into one text file in the following order:
- The Private Key - your_domain_name.key
- The Primary Certificate - your_domain_name.crt
- The Intermediate Certificate - DigiCertCA.crt
- The Root Certificate - TrustedRoot.crt
- Make sure to include the beginning and end tags on each certificate. The result should look like this:
-----BEGIN RSA PRIVATE KEY-----
Your Private Key: your_domain_name.key
-----END RSA PRIVATE KEY----------BEGIN CERTIFICATE-----
Your Primary TLS/SSL certificate: your_domain_name.crt
-----END CERTIFICATE----------BEGIN CERTIFICATE-----
Your Intermediate certificate: DigiCertCA.crt
-----END CERTIFICATE----------BEGIN CERTIFICATE-----
Your Root certificate: TrustedRoot.crt
-----END CERTIFICATE----- - Save the combined file as your_domain_name.pem.
The .pem file is now ready to use.
【推荐】国内首个AI IDE,深度理解中文开发场景,立即下载体验Trae
【推荐】编程新体验,更懂你的AI,立即体验豆包MarsCode编程助手
【推荐】抖音旗下AI助手豆包,你的智能百科全书,全免费不限次数
【推荐】轻量又高性能的 SSH 工具 IShell:AI 加持,快人一步
· TypeScript + Deepseek 打造卜卦网站:技术与玄学的结合
· 阿里巴巴 QwQ-32B真的超越了 DeepSeek R-1吗?
· 【译】Visual Studio 中新的强大生产力特性
· 【设计模式】告别冗长if-else语句:使用策略模式优化代码结构
· AI与.NET技术实操系列(六):基于图像分类模型对图像进行分类
2017-09-25 DNS服务器的维护与故障排除
2017-09-25 Unbound服务的安装与运行管理
2017-09-25 DNS域名解析
2015-09-25 telnet IP不通/sybase central工具无法连接到数据库
2014-09-25 将samba加入到windows域《转载》
2014-09-25 idmap_ad — Samba's idmap_ad Backend for Winbind《转载》
2014-09-25 Enabling Active Directory Authentication for VMWare Server running on Linux《转载》