Keep PFX copies current as your PEM certificates renew, and turn PFX bundles back into PEM
10K+
cert-converter keeps PFX copies of your certificates current as they renew, for apps that accept only PFX. It does not request certificates or restart the apps that read them.
cert-converter renews the PFX file your app reads each time its certificate renews.
<name>.crt and <name>.key pair, with the chain from the .crt file.cert-converter is built for people whose reverse proxy or certificate tool already renews certificates as files, and who run an app that takes only PFX. Examples are .NET apps, Windows tools and the Synology services that take only PFX. It reads <name>.crt and <name>.key pairs, the way Caddy saves each site's certificate. Certbot's fullchain.pem and privkey.pem are not read. Your app must reread the PFX file, or be restarted, to use a renewed certificate.
You need Docker on an amd64 or arm64 machine, and read access to the certificate files for the container's user.
Consider acme.sh if you want your certificate tool to write the PFX file itself. Its --to-pkcs12 command exports a certificate and key as a password-protected PFX file.
cert-converter is free software under the GPL-3.0-or-later license.
docker pull cplieger/cert-converter:latest
Also published to ghcr.io/cplieger/cert-converter with identical images and tags. Release versions are tagged vX.Y.Z alongside latest.
# Example compose for cert-converter. See the README for all configuration options and hardening.
services:
cert-converter:
image: ghcr.io/cplieger/cert-converter:latest
container_name: cert-converter
restart: unless-stopped
# In .env, set PUID and PGID to the user and group that own the certificate files.
# Create the output folder and run "sudo chown 1000:1000" on it, with those numbers, before the first start.
user: "${PUID:-1000}:${PGID:-1000}"
environment:
# Put PFX_PASSWORD=<a password> in .env. The container does not start without one.
# docker inspect shows this value. See README "Security" to use a secret file instead.
PFX_PASSWORD: "${PFX_PASSWORD:-}"
# warn keeps converted files whose certificate is gone, sync deletes them, keep stays silent.
# Use sync only once /input holds every certificate you want converted.
OUTPUT_LIFECYCLE: "${OUTPUT_LIFECYCLE:-warn}"
PFX_ENCODER: "modern2023" # modern2023, modern2026, legacy, or legacyrc2
volumes:
# The user above must be able to read this folder. See README "Quick start".
- "/path/to/certificates:/input:ro"
- "/path/to/converted/output:/output"
GPL-3.0-or-later. See LICENSE. The image carries the license text of every bundled component under /usr/share/licenses/.
Content type
Image
Digest
sha256:0fd4902b2…
Size
3.3 MB
Last updated
about 19 hours ago
docker pull cplieger/cert-converter