Certificate & Private Key Match Checker
Verify whether an X.509 certificate and RSA or EC private key belong together without uploading either file.
Certificate and private key
X.509 certificate
Paste a PEM certificate or upload a .pem, .crt, or .cer file.
Private key
Paste an RSA or EC private key in PKCS#1, SEC1, or PKCS#8 format.
Key verification
Confirm that a certificate matches its private key
Matching the certificate and private key is a common troubleshooting step when configuring TLS servers, reverse proxies, load balancers, and application gateways.
What this tool checks
The checker compares the public key derived from the supplied private key with the public key embedded in the X.509 certificate to determine whether they belong to the same key pair.
What it does not verify
A matching result does not validate the certificate chain, expiration date, revocation status, hostname, or whether the certificate is trusted by browsers or operating systems.
Guide
About Certificate and Private Key Match Checker
A TLS certificate must be deployed with the private key that corresponds to the public key embedded in the certificate.
This checker derives the public key from the supplied private key and compares it with the certificate public key.
A match confirms key-pair ownership but does not prove that the certificate is trusted, valid, or suitable for a hostname.
How matching works
The checker extracts both public keys and compares their encoded key material rather than relying on filenames or labels.
Supported workflows
Use the tool when replacing certificates, migrating servers, troubleshooting TLS startup errors, or reviewing certificate inventories.
- RSA certificates and keys
- Elliptic-curve certificates and keys
- PEM certificate input
- Local comparison
Why files may not match
The certificate may have been issued from another CSR, the server may be using an old key, or files may have been copied from different environments.
What a match does not prove
It does not validate expiration, hostname, chain trust, revocation, or certificate policy.
FAQ
Frequently asked questions
How does the checker determine a match?
It compares the certificate public key with the public key derived from the private key.
Does it support RSA and EC keys?
Yes, where the browser and parser support the supplied formats.
Can matching files still fail on a server?
Yes. The chain, file permissions, certificate format, hostname, or server configuration may still be incorrect.
Does a match prove the certificate is trusted?
No. It proves only that the certificate and private key belong to the same key pair.
Why does renewal sometimes create a mismatch?
A new CSR may have been generated with a new private key while the server still references the old key.
Is my private key uploaded?
The comparison is intended to run locally in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
X.509 Certificate Decoder
Decode certificate identity, validity, algorithms, key details, and fingerprints locally.
PKI & Certificates
Certificate Generator
Generate self-signed Root CA, TLS server, and TLS client certificates with RSA or EC keys.
PKI & Certificates
CSR Decoder
Decode PKCS#10 certificate signing requests and review requested identities, keys, and extensions.
PKI & Certificates
Public & Private Key Analyzer
Identify PEM and OpenSSH key algorithms, formats, sizes, curves, and fingerprints locally.
PKI & Certificates
PEM / DER Converter
Convert certificates, CSRs, public keys, and private keys between PEM, DER, and Base64.
PKI & Certificates
JWK & JWKS Inspector
Inspect JSON Web Keys, review JWKS collections, and generate RFC 7638 thumbprints.
PKI & Certificates