Match
Key and certificate — are they a pair?
One check before you restart the server: does the key match the certificate or not.
Your browser reads the private key and passes it nowhere. But the rule stands: if a key has already been through somebody else’s online service, treat it as known to strangers and reissue the certificate.
Two files
When this saves you
- Before restarting a server with a new certificate — so the error does not surface on the live site.
- When a folder holds several keys and it is unclear which one belongs to which certificate.
- After moving a site, when the files were copied by hand and could have been mixed up.
Common questions
Are you sure you cannot see my key?
The page makes no network request at all — you can see that in the developer tools, Network tab. The key is read inside the tab and disappears with it.
My key starts with BEGIN RSA PRIVATE KEY. What now?
That is the same key in a different wrapper. Convert it to PKCS#8 on your own machine — the command touches no network and does not change the key:
openssl pkcs8 -topk8 -nocrypt -in old.key -out new.key