같은 인증서와 키라도 서비스마다 요구하는 형식이 다르다. 형식과 쓰는 곳은 다음과 같다.
| 형식 | 확장자 | 담는 것 | 쓰는 곳 |
|---|---|---|---|
| PEM | .crt .pem .key |
Base64 텍스트. 인증서와 키를 따로 둔다 | nginx · Apache · OpenSSL · 대부분의 Linux 서비스 |
| DER | .der .cer |
PEM 을 바이너리로 | Java · Windows 일부 |
| PKCS#12[1] | .p12 .pfx |
인증서 + 키 + 체인을 한 파일에, 비밀번호로 보호 | IIS · Windows · Java · 브라우저 가져오기 |
| Java KeyStore | .jks |
Java 전용 저장소 | Tomcat · Kafka · Hadoop 계열 |
변환은 모두 openssl[2] 과 JDK 의 keytool 로 한다.
키 파일 머리에 다음처럼 적혀 있으면 비밀번호가 걸린 키다.
-----BEGIN ENCRYPTED PRIVATE KEY-----
또는 옛 형식에서는 다음과 같다.
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-256-CBC,C94C559628C78A54B3969D399A5C74F8
서비스가 기동할 때마다 비밀번호를 물어보게 되므로 서버용 키는 보통 푼다.
openssl rsa -in encrypted.key -out decrypted.key
# RSA 가 아닌 키(EC 등)는 pkey 로 같은 방식으로 푼다
openssl pkey -in encrypted.key -out decrypted.key
openssl pkcs12 -export -name haedongg.net \
-in haedongg.net.crt -inkey haedongg.net.key -certfile ca.crt \
-out haedongg.net.p12
-certfile 로 CA(체인) 인증서를 함께 넣는다. 없으면 빼도 된다.-name 은 저장소 안의 별칭(alias)이다. Java 로 가져갈 때 이 이름을 쓴다.Windows · Java 8 이하처럼 옛 알고리즘(RC2 · 3DES)만 읽는 곳에 줄 파일은 OpenSSL 3 에서 -legacy 를 붙여 만든다.
openssl pkcs12 -export -legacy -name haedongg.net -in haedongg.net.crt -inkey haedongg.net.key -out haedongg.net.p12
# 인증서만
openssl pkcs12 -in ad-CA.p12 -clcerts -nokeys -out ad-CA.crt
# 키만 (-nodes 를 주면 비밀번호 없는 키로 뽑는다)
openssl pkcs12 -in ad-CA.p12 -nocerts -nodes -out ad-CA.key
# CA 체인만
openssl pkcs12 -in ad-CA.p12 -cacerts -nokeys -out chain.crt
옛 알고리즘으로 만들어진 p12 를 OpenSSL 3 이 읽지 못하면 여기에도 -legacy 를 붙인다.
openssl x509 -in cert.pem -outform DER -out cert.der
openssl x509 -in cert.der -inform DER -out cert.pem
keytool -importkeystore \
-srckeystore haedongg.net.p12 -srcstoretype PKCS12 \
-destkeystore haedongg.net.jks -deststoretype JKS \
-alias haedongg.net
Java 9 이상은 PKCS#12 를 기본 저장소 형식으로 쓰므로 .p12 를 그대로 keystore 로 지정해도 된다. JKS 는 옛 도구가 요구할 때만 만든다.
CA 인증서를 신뢰 저장소(truststore)에 넣을 때는 -importcert 다.
keytool -importcert -alias haedong-ca -file ca.crt -keystore truststore.jks
keytool -list -v -keystore truststore.jks
openssl x509 -noout -subject -issuer -dates -in haedongg.net.crt
openssl pkcs12 -info -in haedongg.net.p12 -nokeys
# 키와 인증서가 짝인지 — 두 값이 같아야 한다
openssl x509 -noout -modulus -in haedongg.net.crt | openssl md5
openssl rsa -noout -modulus -in haedongg.net.key | openssl md5
RFC 7292 — PKCS #12: Personal Information Exchange Syntax v1.1. 2026-09-20 확인. https://www.rfc-editor.org/rfc/rfc7292.html ↩︎
openssl-pkcs12(1) — 2026-09-20 확인. https://docs.openssl.org/master/man1/openssl-pkcs12/ ↩︎