Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Export the certificate as a password-protected PKCS#12 archive—usually a .pfx or .p12 file—with the private key included. A .cer, .crt, or certificate-only .pem file normally contains only the public certificate and will not let a new computer authenticate, sign, decrypt, or connect as the original device.
Before you begin
- Do not wipe, recycle, or reset the old laptop yet.
- Make sure you can sign in to the original Windows account, macOS user account, or Firefox profile.
- Identify the application that uses the certificate: VPN, mail, client authentication, signing software, TLS, or another service.
- Prepare a secure destination for the exported file and a strong, unique export password.
- Check that the certificate is still valid and that you actually need to move it.
An X.509 certificate contains an identity, a public key, issuer information, and validity details. The associated private key is separate and must remain secret. Microsoft explains the distinction between certificates, public keys, and private keys in its certificate documentation.
Choose the store that owns the certificate
| Where it is stored | Use |
|---|---|
| Windows computer store | certlm.msc |
| Windows user store | certmgr.msc |
| macOS Keychain | Keychain Access |
| Firefox certificate database | Firefox Settings > Certificates |
| Smart card, TPM, HSM, or security token | Use the device or request reissuance; the private key may not be exportable |
If the destination asks for a “certificate and private key,” use a .pfx or .p12. These are commonly interchangeable extensions for a PKCS#12 container. A .p7b or PKCS#7 file can carry certificates and chains but does not carry the private key.
Recommended Free Tools
Check whether the private key is available
The certificate alone cannot recreate or recover its private key. On Windows, open the certificate properties or begin the export wizard. If Yes, export the private key is available, the key is present and the provider allows export. If only No, do not export the private key is available, the key may be missing, associated with another user, non-exportable, hardware-backed, or inaccessible.
#1 Best Overall
- Certified to FIPS 197 - High-level information security standard approved by the U.S. Government
- Brute-Force Password Attack Protection - Data is automatically erased after 6 failed access attempts. The data and encryption key are securely destroyed and the crypto drive is reset
- Rugged Double-Layer Waterproof* Design - Protects the crypto drive against knocks, drops, break-in and submerging in water. The electronics are shielded by a hardended inner case. The rubberised silicone outer casing provides a final layer of protection
- Auto-lock - The crypto drive will automatically encrypt all data and lock when removed from a PC/Mac or when the screen saver or "computer lock" function is activated on the host PC/Mac
- Secure Entry - Data cannot be accessed without the correct high-strength alphanumeric 8-16 character password. A password hint option is available. The password hint cannot match the password
On macOS, look for a certificate shown with its associated private key as a digital identity. Selecting only the public certificate can create a certificate-only export. On Firefox, check Your Certificates, because Firefox may maintain its own certificate database rather than using the operating-system store.
Windows: export from the certificate store
Local computer store
- Sign in to the old laptop with an account that can access the certificate.
- Press Windows+R, enter
certlm.msc, and press Enter. - Open Personal > Certificates.
- Find the certificate by subject, issuer, expiration date, or thumbprint.
- Right-click it and select All Tasks > Export.
- In the Certificate Export Wizard, select Yes, export the private key.
- Choose Personal Information Exchange – PKCS #12 (.PFX).
- Enable Include all certificates in the certification path if possible.
- Set a strong export password, choose a protected location, and finish the wizard.
Microsoft documents this workflow in its guide to exporting a certificate with its private key.
Current-user store
If the certificate is not in the local computer store, check the signed-in user’s store. Press Windows+R, run certmgr.msc, and open Personal > Certificates. Repeat the same export process. Checking only certlm.msc can make a user certificate appear to be missing.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #2
- Certified to FIPS 197 - High-level information security standard approved by the U.S. Government
- Brute-Force Password Attack Protection - Data is automatically erased after 6 failed access attempts. The data and encryption key are securely destroyed and the crypto drive is reset
- Auto-lock - The crypto drive will automatically encrypt all data and lock when removed from a PC/Mac or when the screen saver or "computer lock" function is activated on the host PC/Mac
- Secure Entry - Data cannot be accessed without the correct high-strength alphanumeric 8-16 character password. A password hint option is available. The password hint cannot match the password
- SuperSpeed USB 3.0 - Transfer all your confidential files and folders faster than ever before. Works on both PC & Mac
If the certificate belongs to another Windows profile, log in to that original profile if possible. Copying certificate-store files from the disk is not a substitute for an authenticated export because Windows protects private keys through the user profile and cryptographic provider.
macOS: export from Keychain Access
- Open Applications > Utilities > Keychain Access.
- Check likely keychains such as login and System. System Roots generally contains trust certificates rather than your personal identity.
- Search by subject, issuer, email address, or organization.
- Expand the certificate entry or select the certificate together with its associated private key.
- Choose File > Export Items.
- Save it as a PKCS#12-compatible file, commonly using the
.p12extension. - Set and confirm an export password.
Apple’s Keychain Access instructions note that some items cannot be exported. If Export Items is disabled, the selected item may be non-exportable or hardware-protected. Apple describes the certificate-plus-private-key combination as a digital identity in its PKCS#12 guidance.
Firefox: back up a certificate from Firefox’s own store
- Open Firefox and open Settings.
- Search Settings for certificates, or open the certificate-management section under privacy and security.
- Select View Certificates or Certificate Manager.
- Open Your Certificates.
- Select the relevant personal or client certificate and choose Backup.
- Save the backup as a PKCS#12 file, usually
.p12, and set a backup password.
Firefox’s labels and menu placement vary by release, so Settings search is more reliable than memorizing an older menu path. DigiCert documents the Your Certificates > Backup workflow for Windows and macOS.
Rank #3
- Certified to FIPS 197 - U.S. Government Approved High Level Information Security Standard.
- Protection against brute force password attacks - Data is automatically erased after 6 unsuccessful access attempts. The data of the USB flash drive type c encryption with dual connectors is destroyed and the cryptographic drive is reset.
- Durable dual-layer waterproof design* — Protects the crypto reader from bumps, drops, run-in and immersion in water. The electronics are protected by a hardened internal case. Rubberized silicone outer case provides a final layer of protection.
- Auto-Lock —The cryptographic key automatically encrypts all data and locks when removed from a PC/Mac or when screen protection or "computer lock" is enabled.
- Secure Entry —Data on these flash drives cannot be accessed without the correct alphanumeric password of 8 to 16 characters. A password indication option is available for this flash drive. The hint cannot match the password.
OpenSSL: create, inspect, or split a PKCS#12 file
OpenSSL cannot recover a private key from a certificate. It can package files when the private key is already available.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Create a PKCS#12 archive
openssl pkcs12 -export
-out certificate.p12
-inkey private-key.pem
-in certificate.pem
-certfile chain.pem
Omit -certfile chain.pem if you do not have a chain file. OpenSSL will prompt for an export password. See the OpenSSL PKCS#12 documentation for current options.
Inspect without extracting
openssl pkcs12 -in certificate.p12 -info -noout
This prompts for the archive password and displays its contents without writing extracted key material to disk.
Rank #4
- FIPS 197 with XTS-AES 256-bit Encryption: Provides business-grade security with hardware-based encryption to protect your sensitive data
- Brute Force and BadUSB Attack Protection: Safeguards against unauthorized access attempts and malicious USB attacks with digitally-signed firmware
- Multi-Password Option with Complex/Passphrase modes: Offers flexible password configuration options to meet various security requirements and user preferences
- New Passphrase Mode: Enhanced security feature allowing users to create longer, more memorable password phrases for easier access without compromising protection
- Dual Read-Only (Write-Protect) Settings: Enables write protection functionality to prevent accidental data modification or deletion when needed
Extract certificate and key files when required
openssl pkcs12 -in certificate.p12 -clcerts -nokeys -out certificate.pem
openssl pkcs12 -in certificate.p12 -nocerts -out private-key-encrypted.pem
The second command keeps the extracted private key encrypted. Only create an unencrypted key when a specific destination requires it:
openssl pkcs12 -in certificate.p12 -nocerts -noenc -out private-key.pem
OpenSSL 3 documents -noenc; the older -nodes option is deprecated. Treat an unencrypted private-key file as highly sensitive and delete it securely as soon as it is no longer needed.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Verify that the certificate and private key match
Two valid files can still belong to different key pairs. For PEM-formatted RSA or EC material, derive and compare the public-key fingerprints:
Best Value
- XTS-AES 256-bit hardware-encryption
- FIPS 197 certified
- Multi-Password (Admin and User) option with complex/passphrase modes
- Up to 145MB/s Read, 115MB/s Write
openssl x509 -in certificate.pem -pubkey -noout |
openssl pkey -pubin -outform DER |
sha256sum
openssl pkey -in private-key.pem -pubout |
openssl pkey -pubin -outform DER |
sha256sum
The two hashes should be identical. You can also inspect the PKCS#12 archive with openssl pkcs12 -in certificate.p12 -info -noout, then test-import it and confirm that the destination identifies an associated private key.
Import the archive on the new device
- Windows: Open the
.pfxor.p12file, enter the export password, and choose the intended certificate store. A service may require the key to be imported into the local computer store rather than the current-user store. - macOS: Open Keychain Access and choose File > Import Items, or double-click the archive and select the destination keychain. Apple documents this in its Keychain Access guide.
- Firefox: Open Certificate Manager, select the personal-certificate area, and use Import.
- Linux or server software: Use the application’s certificate-import facility. If it requires separate files, extract the certificate, encrypted key, and chain with OpenSSL.
When export fails
| Symptom | Likely reason | Correct next step |
|---|---|---|
| No “Yes, export the private key” option | The key is missing, in another store, or non-exportable | Check the correct user/browser store; otherwise recover or reissue it |
| macOS export is disabled | An item cannot be exported or is hardware-bound | Select the complete identity and check whether the key is on a token |
| The certificate appears but no key does | Certificate-only import or wrong store | Re-export the certificate and private-key identity together |
| The old disk is readable but export fails | Profile, credential, or provider protection | Boot the original installation and account, or contact the PKI administrator |
A smart-card certificate will not produce a .p12 |
The private key is designed to remain on the card | Move the card and middleware, or request a new certificate |
| Import reports a wrong password | Incorrect password, damaged file, or unsupported archive | Re-enter it carefully, verify the file, and create a new export if necessary |
| Import succeeds but the application cannot use it | Wrong store, incomplete chain, unsuitable usage, permissions, or mismatched key | Check the application store, certificate purpose, chain, permissions, and key match |
Non-exportable and hardware-protected keys
Windows can mark a private key with an export policy that prohibits export. Microsoft’s private-key export policy documentation identifies this as an intentional provider-enforced restriction. A TPM, smart card, HSM, Secure Enclave, or other security token may similarly keep the private key inside the device.
Do not try to defeat that policy or use an online converter. The normal alternatives are to move the physical token, install its middleware on the new computer, use an organizational recovery process, or request certificate reissuance.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →If the old laptop no longer boots
- Create a forensic or full-disk image before experimenting.
- Repair or boot the original installation if possible.
- Sign in to the original account and perform a normal export.
- Ask the organization’s PKI administrator whether a backup, reissue, or key-recovery process exists.
For Microsoft AD CS, a Key Recovery Agent may recover an archived private key into a password-protected PKCS#12 file—but only if key archival was configured before issuance. It is not a universal recovery method. See Microsoft’s documentation on key recovery servers.
If a Windows password was reset, the profile was migrated, or the profile is damaged, treat the situation as a profile-recovery problem rather than assuming an administrator can export the key. Administrative access does not override every provider or hardware policy.
Secure-handling checklist
- Use a long, unique export password.
- Transfer the archive over an encrypted channel or protected removable media.
- Never email the archive and its password together.
- Store the archive in an access-controlled location.
- Avoid extracting an unencrypted private key unless the destination requires it.
- Delete temporary plaintext key files securely.
- After testing the new installation, remove unnecessary copies from the old laptop and transfer media.
- If the archive or password may have been exposed, ask the certificate issuer whether the certificate should be revoked and reissued.
Final verification
The migration is complete only when the new device or application can see the certificate and its associated private key, the certificate chain is accepted, the intended usage is permitted, and the actual operation works—for example, VPN login, TLS client authentication, mail decryption, document signing, or server authentication.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

