On Thu, 2022-06-09 at 13:14 +0000, Beilharz, Michael wrote: > well, i use: > > pkcs12 -in "cert.p12" -clcerts -nokeys -out cert.PEM" -passin > pass:<pass> > pkcs12 -in "cert.p12" -nocerts -out tmpkey.PEM -passin pass:<pass> - > passout pass:<pass> Instead of this step you can just use: pkcs12 -in "cert.p12" -nocerts -nodes -out key.pem -passin pass:<pass> if you need unencrypted private key in PEM file. -- Tomáš Mráz, OpenSSL