What Is a PFX Certificate File and How Do You Create It?
Home » What Is a PFX Certificate File and How Do You Create It?
(6 votes, average: 5.00 out of 5)
Tired of maintaining and securing too many digital certificates and keys? You’re not alone. 72% of organizations say the increasing number of keys and certificates they use is driving them crazy. To ease the pain, learn how to create a PFX file to bundle your certificate and its related key in a single, secure file
Looking to create a .pfx file for your new organization validation (OV) code signing certificate? If you opted for the default certificate provisioning method, then you don’t have to do anything extra. This is because your certificate issuer will handle everything on the back end to meet new industry standards. Now, all you have to do is wait for your certificate and key to arrive pre-installed on a hardware security token. You’ll no longer have to manually combine your certificate and key files to create a PFX certificate for code signing certificates.
In the first three months of 2023, organizations had to fight an average of 1,248 attacks per week. From T-Mobile falling victim to yet another data breach — the second since the start of the year — to the German biotech company Evotec taking its systems offline due to a cyber attack, the volume of security incidents doesn’t seem to stop.
Digital certificates enable organizations to encrypt and keep data and sensitive information safe from attackers. However, in order to use one, it often requires combining the private key and the certificate files into a single bundle. The solution? A personal information exchange file (.pfx or PFX file).
Have we piqued your interest? Learn what a PFX file is and what it does; then discover how to create a PFX certificate in six quick steps.
A PFX file is another term for a public key cryptographic standard #12 (PKCS #12) file because it’s one of two file extensions that’s used for this type of file (.p12 and .pfx). Creating a .pfx file is a convenient and secure way to store important cryptographic assets in a password-protected bundle:
A digital certificate (e.g., a code signing certificate, SSL/TLS certificate, client authentication certificate, etc.), and
The matching private key file.
Image caption: The graphic shows how a PFX certificate is created and how it can reduce the risks of private key theft.
Think of it like one of those briefcases used by James Bond, where your digital certificate and keys can be locked up to keep them safe from evil-doers.
Once created, a PFX file has the same capabilities as the components included in the bundle; therefore, it can be used to:
Why is it better to separate the digital certificate and key file? Because a PFX certificate is:
Secure. As it’s protected by a password and its integrity is assured via cryptographic hashing, it adds an extra layer of security to the file bundle. Moreover, the fact that it also facilitates data encryption in transit (e.g., through SSL/TLS certificates) can help organizations to reach compliance with privacy and security regulation (e.g., the Payment Card Industry Data Security Standard[PCI-DSS] where strong data encryption is one of the requirements ).
Easier to Manage. It reduces the burden on administrators by cutting down the number of files to secure, manage, and transfer between applications or servers.
Helpful in case of system failure. Do you have a backup of your certificates and keys? You don’t? Save them as .pfx files, and store them onto a secure USB token to keep them safe, and always at hand in case the worst happens. Don’t share it with anyone though. Your private key must remain private.
So, what do you think? Are you in? Good! Let’s learn how to create a PFX certificate in six easy-peasy steps.
How Can I Generate a PFX File?
In December 2022, three GitHub code signing keys were stolen. The certificates were revoked in February 2023. The security breach was contained in part thanks to the fact that strong passwords protected the certificates and keys.
Are you going to be the next victim? Hopefully not. Wrapping together your digital certificate and its related key in a single, password-protected file can help you dodge a bullet. C’mon, let’s start securing those precious assets with the help of Windows GUI-based wizard. All you need is the following:
A Windows device,
A digital certificate issued by a certificate authority (e.g., a code signing or an SSL/TSL certificate with extension .cert, .crt, or .pem), and
Your cryptographic key file (i.e., the corresponding public and private key with the .key extension).
Got everything you need? Let’s go!
1. Open the Certificate Management Console
Go to your Windows start bar and search for your certificate management console by typing ”cert” into the field. Select it and click on Open.
Image caption: The Screenshot shows how to open the Windows management console.
2. Pick Your Digitally Signed Certificate
Double-click the Personal folder in the pop-up window to view the Certificate folder, then click on that to open it.
Navigate to the certificate you want to use to create your .PFX certificate.
To select it, right-click on it, click All Tasks, and then Export.
Image caption: The screenshot shows how to get to the personal certificates folder to select the certificate you wish to include in your .PFX file.
This will open the Certificate Export Wizard. Press Next to continue to the next screen.
Image caption: A screenshot of the Certificate Export Wizard. Click Next to start creating your PFX file.
3. Export Your Private Key
In the Certificate Export Wizard (as shown below), press Next and select Yes, export the private key.
Click Next again.
Image caption: A screenshot that shows how to export the private key.
4. Select the Certificate’s Format
This is where you’ll make selections to specify your file type and which certificates you want to include.
Check the box Personal information exchange – PKCS #12 (.pfx). Sounds confusing? PCKS #12 is the standard archive file format used by PFX files to bundle multiple cryptographic objects (e.g., digital certificates, key files) in a single file. Published by RSA Laboratories, is among the most complex cryptographic protocols.
Select Include all certificates in the certification path if possible and click Next. Why? To add another layer of security, the CA uses an intermediate certificate (i.e., a digital certificate issued by the CA itself and used to issue other certificates) to sign your certificate. This last option will ensure that the CA intermediate root certificate will be included in your PFX file, too.
Image caption: A screenshot showing how to select the .pfx file format
5. Enter a Password for Your Private Key
To secure your key, type a strong password of your choice, and repeat it to confirm it. Click on Next.
Image caption: A screenshot that shows how to protect the private key with a password.
6. Choose Where to Store Your PFX Certificate
Hit the Browse button to define the name of your .PXF file and where it’ll be saved. For demonstration purposes only, I have saved it on my desktop (as shown in the screenshot below).
Click Next, followed by Finish. Congratulations! You’ve just generated your first PFX certificate!
Image caption: A screenshot showing how to select the location where to save your PFX certificate.
Image caption: A screenshot that shows the final step to how to create a .PXF certificate.
Image caption: A screenshot confirming that the creation of your .pfx file was successful.
Last but not least, navigate to the folder where you saved your PFX file and check to ensure it’s listed to verify that everything worked correctly.
Image caption: A screenshot that shows how to verify if the .PFX file you’ve just generated has been saved in the folder of your choice.
Are you an advanced user and you’d rather use the terminal to generate your .pfx file? You can do that with OpenSSL.
Final Thoughts on What a PFX File Is and How You Create It
As you’ve just learned, adding another layer of security to your digital certificates isn’t rocket science. Now that you know how to create a PFX file, depending on the type of certificate it is you’ve created a .pfx file for, you can use it to:
Sign your codes and applications (code signing certificate),
Secure the data transmission between the client and your web server (SSL/TLS certificate),
Authenticate users or devices (client authentication certificate or device certificate) or
Encrypt and sign your emails (email signing certificate or S/MIME certificate).
Done? Good, now you’re really ready to enjoy its benefits and start to crack down on potential attacks.
Code Signing Best Practices
Want to keep your software and code safe?
Enter your contact information below below to receive your FREE Best Practices PDF:
Contact details collected by CodeSigningStore.com may be used to send you requested information, blog update notices, and for marketing purposes. Learn more…
New users – if this is your first time purchasing a cloud signing product from us, check the email address entered during enrollment for a message from DigiCert. Create your password and follow this guide.
Existing users – if you’ve purchased a cloud signing certificate in this account before, you already have an account. We’ve update your DigiCert CertCentral account to allow another Code Signing Certificate request. Login to your account here.
suspension note
In order to comply with U.S. export control and economic sanctions laws and regulations, as well as our corporate policies, we do not support users accessing our applications from Cuba, Iran, North Korea, Syria, and the regions of Crimea, Donetsk People’s Republic (DNR) and Luhansk People’s Republic (LNR) of Ukraine without prior approval from the U.S. government.
Please be aware that these restrictions apply even when a user is on temporary travel to embargoed regions although the user may not normally reside there. If you believe that you have reached this page in error, please reach out to support.
Code Signing Certificate Delivery Options
Industry standards set by the CA/B Forum now require that all code signing certificate keys be stored on a FIPS-compliant hardware security module (HSM) or hardware token. This is an industry-wide countermeasure against the rise in breaches associated with stolen signing keys. Only certificates that follow these requirements will be trusted by Microsoft Windows and other platforms.
We offer several options to deliver your code signing certificate in compliance with these new requirements:
Easiest Option: Token + Shipping
This is the simplest option and what we recommend for most customers. DigiCert will ship a USB eToken to you, then you’ll use DigiCert’s provided software to download and install the certificate onto your USB Token.
You’ll be able to plug the USB token into your computer or server then sign files using your preferred tool (eg. SignTool.exe, JarSigner, etc.)
Use an Existing Token
If you already own a compatible USB eToken (SafeNet 5110 CC, SafeNet 5110 FIPS, or SafeNet 5110+ FIPS), you can use DigiCert’s provided software to download and install the certificate onto your USB token.
Advanced Option: Install on a Hardware Security Module (HSM)
If you use a cloud or on-prem hardware security module (HSM), you can choose this option to download and install your certificate onto your HSM. DigiCert will send you an email asking you to confirm that your HSM meets the security standards, then they’ll deliver the certificate to you digitally for installation.
Any FIPS 140 Level 2, Common Criteria EAL 4+, or equivalent HSM is compatible for this option. You can use an HSM you manage directly or you may use a key storage/vault solution that uses a compliant HSM (for example, Azure Key Vault or AWS KMS).
Code Signing Certificate Delivery Options
Industry standards set by the CA/B Forum now require that all code signing certificate keys be stored on a FIPS-compliant hardware security module (HSM) or hardware token. This is an industry-wide countermeasure against the rise in breaches associated with stolen signing keys. Only certificates that follow these requirements will be trusted by Microsoft Windows and other platforms.
We offer several options to deliver your code signing certificate in compliance with these new requirements:
Easiest Option: Get your certificate shipped from Sectigo on a USB token
This is the simplest option and what we recommend for most customers. Just choose one of these options to have your code signing certificate and key shipped to you on a FIPS-compliant eToken (USB token):
Delivery Option
Shipping Details
USB Token + Shipping (US)
Ground shipping to addresses within the United States.
USB Token + Expedited Shipping (US)
Air express shipping to addresses within the United States.
USB Token + International Shipping (non-US)
Choose this option if your shipping address is not in the United States.
You’ll be able to plug the USB token into your computer or server then sign files using your preferred tool (eg. SignTool.exe, JarSigner, etc.)
Advanced Option: Install on your own HSM or hardware token
If you already own a compliant token or HSM, you can choose this option to download and install the certificate onto your supported device:
Luna Network Attached HSM V7.x
YubiKey 5 FIPS Series
Only the listed models are compatible. For compatibility with other HSM models, please choose a DigiCert or GoGetSSL code signing certificate.
Code Signing Certificate Delivery Options
Industry standards set by the CA/B Forum now require that all code signing certificate keys be stored on a FIPS-compliant hardware security module (HSM) or hardware token. This is an industry-wide countermeasure against the rise in breaches associated with stolen signing keys. Only certificates that follow these requirements will be trusted by Microsoft Windows and other platforms.
We offer several options to deliver your code signing certificate in compliance with these new requirements:
Easiest Option: Get your certificate shipped from Comodo CA on a USB token
This is the simplest option and what we recommend for most customers. Just choose one of these options to have your code signing certificate and key shipped to you on a FIPS-compliant eToken (USB token):
Delivery Option
Shipping Details
USB Token + Shipping (US)
Ground shipping to addresses within the United States.
USB Token + Expedited Shipping (US)
Air express shipping to addresses within the United States.
USB Token + International Shipping (non-US)
Choose this option if your shipping address is not in the United States.
You’ll be able to plug the USB token into your computer or server then sign files using your preferred tool (eg. SignTool.exe, JarSigner, etc.)
Advanced Option: Install on your own HSM or hardware token
If you already own a compliant token or HSM, you can choose “Install on Existing HSM” to download and install the certificate onto your supported device:
Luna Network Attached HSM V7.x
YubiKey 5 FIPS Series
Only the listed models are compatible. For compatibility with other HSM models, please choose a DigiCert or GoGetSSL code signing certificate.