Certificate & Private Key Match Checker

Verify whether an X.509 certificate and RSA or EC private key belong together without uploading either file.

Browser onlyRSA & ECNo upload

Certificate and private key

X.509 certificate

Paste a PEM certificate or upload a .pem, .crt, or .cer file.

Private key

Paste an RSA or EC private key in PKCS#1, SEC1, or PKCS#8 format.

Key verification

Confirm that a certificate matches its private key

Matching the certificate and private key is a common troubleshooting step when configuring TLS servers, reverse proxies, load balancers, and application gateways.

What this tool checks

The checker compares the public key derived from the supplied private key with the public key embedded in the X.509 certificate to determine whether they belong to the same key pair.

What it does not verify

A matching result does not validate the certificate chain, expiration date, revocation status, hostname, or whether the certificate is trusted by browsers or operating systems.

Guide

About Certificate and Private Key Match Checker

A TLS certificate must be deployed with the private key that corresponds to the public key embedded in the certificate.

This checker derives the public key from the supplied private key and compares it with the certificate public key.

A match confirms key-pair ownership but does not prove that the certificate is trusted, valid, or suitable for a hostname.

How matching works

The checker extracts both public keys and compares their encoded key material rather than relying on filenames or labels.

Supported workflows

Use the tool when replacing certificates, migrating servers, troubleshooting TLS startup errors, or reviewing certificate inventories.

  • RSA certificates and keys
  • Elliptic-curve certificates and keys
  • PEM certificate input
  • Local comparison

Why files may not match

The certificate may have been issued from another CSR, the server may be using an old key, or files may have been copied from different environments.

What a match does not prove

It does not validate expiration, hostname, chain trust, revocation, or certificate policy.

FAQ

Frequently asked questions

How does the checker determine a match?

It compares the certificate public key with the public key derived from the private key.

Does it support RSA and EC keys?

Yes, where the browser and parser support the supplied formats.

Can matching files still fail on a server?

Yes. The chain, file permissions, certificate format, hostname, or server configuration may still be incorrect.

Does a match prove the certificate is trusted?

No. It proves only that the certificate and private key belong to the same key pair.

Why does renewal sometimes create a mismatch?

A new CSR may have been generated with a new private key while the server still references the old key.

Is my private key uploaded?

The comparison is intended to run locally in your browser.

Continue exploring

Useful tools for the next step in the same workflow.