PKCS#12 / PFX Inspector
Inspect password-protected PKCS#12 containers, review certificates, private-key bags, aliases, and local key identifiers without uploading your file.
PKCS#12 input
Choose a .p12 or .pfx file
The file is read locally in your browser.
PKCS#12 containers
Inspect certificates and key material stored in a PFX file
PKCS#12 (PFX) files are commonly used to transport certificates together with their corresponding private keys and associated metadata.
What this tool inspects
Review certificates, private-key bags, friendly names, local key identifiers, certificate chains, and cryptographic metadata stored inside PKCS#12 or PFX containers.
Protect exported PFX files
PKCS#12 files often contain private keys. Keep them encrypted with strong passwords, limit access, and avoid sharing production PFX files outside trusted environments.
Guide
About PKCS#12 and PFX Inspector
PKCS#12 containers are commonly used to transport certificates together with private keys and metadata.
This inspector opens supported PFX or P12 files and lists certificates, key bags, aliases, and identifiers.
Because PKCS#12 files can contain private keys, handle them only in trusted environments.
What a PKCS#12 file can contain
A container can hold multiple certificates, private keys, and attributes.
- End-entity certificate
- Intermediate certificates
- Private-key bags
- Friendly names
- Local key identifiers
Password protection
PKCS#12 commonly uses a password for integrity and encryption, but actual security depends on the algorithms and password strength.
Matching keys and certificates
localKeyId and public-key comparison can help associate a private key with its certificate.
Private-key handling
Do not upload production PFX files to untrusted systems or share them through insecure channels.
FAQ
Frequently asked questions
What is the difference between PFX and P12?
They are commonly used file extensions for PKCS#12 containers.
Can PKCS#12 contain private keys?
Yes. That is one of its common purposes.
Why is a password required?
The password may protect encrypted contents and integrity information.
What is a friendly name?
It is a human-readable attribute associated with a bag or certificate.
What is localKeyId?
It is an attribute often used to associate a certificate with its private key bag.
Is the file uploaded?
Inspection is intended to occur locally in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
X.509 Certificate Decoder
Decode certificate identity, validity, algorithms, key details, and fingerprints locally.
PKI & Certificates
Certificate & Private Key Match Checker
Verify whether an X.509 certificate and RSA private key contain the same public key.
PKI & Certificates
PEM Bundle Inspector
Inspect mixed PEM bundles and identify certificates, keys, CSRs, CRLs, and PKCS#7/CMS blocks.
PKI & Certificates
PKCS#7 / P7B Inspector
Inspect PKCS#7 and CMS containers, embedded certificates, and signer information.
PKI & Certificates
CSR Decoder
Decode PKCS#10 certificate signing requests and review requested identities, keys, and extensions.
PKI & Certificates
Public & Private Key Analyzer
Identify PEM and OpenSSH key algorithms, formats, sizes, curves, and fingerprints locally.
PKI & Certificates