Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Export the certificate as a password-protected PKCS#12 archive—usually a .pfx or .p12 file—with the private key included. A .cer, .crt, or certificate-only .pem file normally contains only the public certificate and will not let a new computer authenticate, sign, decrypt, or connect as the original device.

Before you begin

  • Do not wipe, recycle, or reset the old laptop yet.
  • Make sure you can sign in to the original Windows account, macOS user account, or Firefox profile.
  • Identify the application that uses the certificate: VPN, mail, client authentication, signing software, TLS, or another service.
  • Prepare a secure destination for the exported file and a strong, unique export password.
  • Check that the certificate is still valid and that you actually need to move it.

An X.509 certificate contains an identity, a public key, issuer information, and validity details. The associated private key is separate and must remain secret. Microsoft explains the distinction between certificates, public keys, and private keys in its certificate documentation.

Choose the store that owns the certificate

Where it is stored Use
Windows computer store certlm.msc
Windows user store certmgr.msc
macOS Keychain Keychain Access
Firefox certificate database Firefox Settings > Certificates
Smart card, TPM, HSM, or security token Use the device or request reissuance; the private key may not be exportable

If the destination asks for a “certificate and private key,” use a .pfx or .p12. These are commonly interchangeable extensions for a PKCS#12 container. A .p7b or PKCS#7 file can carry certificates and chains but does not carry the private key.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check whether the private key is available

The certificate alone cannot recreate or recover its private key. On Windows, open the certificate properties or begin the export wizard. If Yes, export the private key is available, the key is present and the provider allows export. If only No, do not export the private key is available, the key may be missing, associated with another user, non-exportable, hardware-backed, or inaccessible.

#1 Best Overall
Integral 16GB Crypto-197 256-Bit Hardware Encrypted 3.0 USB Secure Flash Memory Drive - Certified to FIPS 197, Brute-Force Password Attack Protection & Rugged Double-Layer Waterproof Design
  • Certified to FIPS 197 - High-level information security standard approved by the U.S. Government
  • Brute-Force Password Attack Protection - Data is automatically erased after 6 failed access attempts. The data and encryption key are securely destroyed and the crypto drive is reset
  • Rugged Double-Layer Waterproof* Design - Protects the crypto drive against knocks, drops, break-in and submerging in water. The electronics are shielded by a hardended inner case. The rubberised silicone outer casing provides a final layer of protection
  • Auto-lock - The crypto drive will automatically encrypt all data and lock when removed from a PC/Mac or when the screen saver or "computer lock" function is activated on the host PC/Mac
  • Secure Entry - Data cannot be accessed without the correct high-strength alphanumeric 8-16 character password. A password hint option is available. The password hint cannot match the password

On macOS, look for a certificate shown with its associated private key as a digital identity. Selecting only the public certificate can create a certificate-only export. On Firefox, check Your Certificates, because Firefox may maintain its own certificate database rather than using the operating-system store.

Windows: export from the certificate store

Local computer store

  1. Sign in to the old laptop with an account that can access the certificate.
  2. Press Windows+R, enter certlm.msc, and press Enter.
  3. Open Personal > Certificates.
  4. Find the certificate by subject, issuer, expiration date, or thumbprint.
  5. Right-click it and select All Tasks > Export.
  6. In the Certificate Export Wizard, select Yes, export the private key.
  7. Choose Personal Information Exchange – PKCS #12 (.PFX).
  8. Enable Include all certificates in the certification path if possible.
  9. Set a strong export password, choose a protected location, and finish the wizard.

Microsoft documents this workflow in its guide to exporting a certificate with its private key.

Current-user store

If the certificate is not in the local computer store, check the signed-in user’s store. Press Windows+R, run certmgr.msc, and open Personal > Certificates. Repeat the same export process. Checking only certlm.msc can make a user certificate appear to be missing.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Integral 8GB Courier-197 256-Bit Hardware Encrypted 3.0 USB Secure Flash Memory Drive - Certified to FIPS 197, Brute-Force Password Attack Protection & Super USB3.0 Transfer Speeds
  • Certified to FIPS 197 - High-level information security standard approved by the U.S. Government
  • Brute-Force Password Attack Protection - Data is automatically erased after 6 failed access attempts. The data and encryption key are securely destroyed and the crypto drive is reset
  • Auto-lock - The crypto drive will automatically encrypt all data and lock when removed from a PC/Mac or when the screen saver or "computer lock" function is activated on the host PC/Mac
  • Secure Entry - Data cannot be accessed without the correct high-strength alphanumeric 8-16 character password. A password hint option is available. The password hint cannot match the password
  • SuperSpeed USB 3.0 - Transfer all your confidential files and folders faster than ever before. Works on both PC & Mac

If the certificate belongs to another Windows profile, log in to that original profile if possible. Copying certificate-store files from the disk is not a substitute for an authenticated export because Windows protects private keys through the user profile and cryptographic provider.

macOS: export from Keychain Access

  1. Open Applications > Utilities > Keychain Access.
  2. Check likely keychains such as login and System. System Roots generally contains trust certificates rather than your personal identity.
  3. Search by subject, issuer, email address, or organization.
  4. Expand the certificate entry or select the certificate together with its associated private key.
  5. Choose File > Export Items.
  6. Save it as a PKCS#12-compatible file, commonly using the .p12 extension.
  7. Set and confirm an export password.

Apple’s Keychain Access instructions note that some items cannot be exported. If Export Items is disabled, the selected item may be non-exportable or hardware-protected. Apple describes the certificate-plus-private-key combination as a digital identity in its PKCS#12 guidance.

Firefox: back up a certificate from Firefox’s own store

  1. Open Firefox and open Settings.
  2. Search Settings for certificates, or open the certificate-management section under privacy and security.
  3. Select View Certificates or Certificate Manager.
  4. Open Your Certificates.
  5. Select the relevant personal or client certificate and choose Backup.
  6. Save the backup as a PKCS#12 file, usually .p12, and set a backup password.

Firefox’s labels and menu placement vary by release, so Settings search is more reliable than memorizing an older menu path. DigiCert documents the Your Certificates > Backup workflow for Windows and macOS.

Rank #3
Integral 4GB Crypto-197 256-Bit 3.0 USB Flash Drive Encrypted - FIPS 197 Certified, Brute Force Password Attack Protection & Waterproof Double Layer Design
  • Certified to FIPS 197 - U.S. Government Approved High Level Information Security Standard.
  • Protection against brute force password attacks - Data is automatically erased after 6 unsuccessful access attempts. The data of the USB flash drive type c encryption with dual connectors is destroyed and the cryptographic drive is reset.
  • Durable dual-layer waterproof design* — Protects the crypto reader from bumps, drops, run-in and immersion in water. The electronics are protected by a hardened internal case. Rubberized silicone outer case provides a final layer of protection.
  • Auto-Lock —The cryptographic key automatically encrypts all data and locks when removed from a PC/Mac or when screen protection or "computer lock" is enabled.
  • Secure Entry —Data on these flash drives cannot be accessed without the correct alphanumeric password of 8 to 16 characters. A password indication option is available for this flash drive. The hint cannot match the password.

OpenSSL: create, inspect, or split a PKCS#12 file

OpenSSL cannot recover a private key from a certificate. It can package files when the private key is already available.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Create a PKCS#12 archive

openssl pkcs12 -export 
  -out certificate.p12 
  -inkey private-key.pem 
  -in certificate.pem 
  -certfile chain.pem

Omit -certfile chain.pem if you do not have a chain file. OpenSSL will prompt for an export password. See the OpenSSL PKCS#12 documentation for current options.

Inspect without extracting

openssl pkcs12 -in certificate.p12 -info -noout

This prompts for the archive password and displays its contents without writing extracted key material to disk.

Rank #4
Kingston IronKey Vault Privacy 50 16GB Encrypted USB
  • FIPS 197 with XTS-AES 256-bit Encryption: Provides business-grade security with hardware-based encryption to protect your sensitive data
  • Brute Force and BadUSB Attack Protection: Safeguards against unauthorized access attempts and malicious USB attacks with digitally-signed firmware
  • Multi-Password Option with Complex/Passphrase modes: Offers flexible password configuration options to meet various security requirements and user preferences
  • New Passphrase Mode: Enhanced security feature allowing users to create longer, more memorable password phrases for easier access without compromising protection
  • Dual Read-Only (Write-Protect) Settings: Enables write protection functionality to prevent accidental data modification or deletion when needed

Extract certificate and key files when required

openssl pkcs12 -in certificate.p12 -clcerts -nokeys -out certificate.pem
openssl pkcs12 -in certificate.p12 -nocerts -out private-key-encrypted.pem

The second command keeps the extracted private key encrypted. Only create an unencrypted key when a specific destination requires it:

openssl pkcs12 -in certificate.p12 -nocerts -noenc -out private-key.pem

OpenSSL 3 documents -noenc; the older -nodes option is deprecated. Treat an unencrypted private-key file as highly sensitive and delete it securely as soon as it is no longer needed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Verify that the certificate and private key match

Two valid files can still belong to different key pairs. For PEM-formatted RSA or EC material, derive and compare the public-key fingerprints:

Best Value
Sale
Kingston Ironkey Locker+ 50 G2 32GB Encrypted USB Drive | FIPS 197 | AES-XTS Protection | Multi-Password Security | USB 3.2 Gen 1 | IKLP50G2/32GB
  • XTS-AES 256-bit hardware-encryption
  • FIPS 197 certified
  • Multi-Password (Admin and User) option with complex/passphrase modes
  • Up to 145MB/s Read, 115MB/s Write
openssl x509 -in certificate.pem -pubkey -noout | 
  openssl pkey -pubin -outform DER | 
  sha256sum
openssl pkey -in private-key.pem -pubout | 
  openssl pkey -pubin -outform DER | 
  sha256sum

The two hashes should be identical. You can also inspect the PKCS#12 archive with openssl pkcs12 -in certificate.p12 -info -noout, then test-import it and confirm that the destination identifies an associated private key.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Import the archive on the new device

  • Windows: Open the .pfx or .p12 file, enter the export password, and choose the intended certificate store. A service may require the key to be imported into the local computer store rather than the current-user store.
  • macOS: Open Keychain Access and choose File > Import Items, or double-click the archive and select the destination keychain. Apple documents this in its Keychain Access guide.
  • Firefox: Open Certificate Manager, select the personal-certificate area, and use Import.
  • Linux or server software: Use the application’s certificate-import facility. If it requires separate files, extract the certificate, encrypted key, and chain with OpenSSL.

When export fails

Symptom Likely reason Correct next step
No “Yes, export the private key” option The key is missing, in another store, or non-exportable Check the correct user/browser store; otherwise recover or reissue it
macOS export is disabled An item cannot be exported or is hardware-bound Select the complete identity and check whether the key is on a token
The certificate appears but no key does Certificate-only import or wrong store Re-export the certificate and private-key identity together
The old disk is readable but export fails Profile, credential, or provider protection Boot the original installation and account, or contact the PKI administrator
A smart-card certificate will not produce a .p12 The private key is designed to remain on the card Move the card and middleware, or request a new certificate
Import reports a wrong password Incorrect password, damaged file, or unsupported archive Re-enter it carefully, verify the file, and create a new export if necessary
Import succeeds but the application cannot use it Wrong store, incomplete chain, unsuitable usage, permissions, or mismatched key Check the application store, certificate purpose, chain, permissions, and key match

Non-exportable and hardware-protected keys

Windows can mark a private key with an export policy that prohibits export. Microsoft’s private-key export policy documentation identifies this as an intentional provider-enforced restriction. A TPM, smart card, HSM, Secure Enclave, or other security token may similarly keep the private key inside the device.

Do not try to defeat that policy or use an online converter. The normal alternatives are to move the physical token, install its middleware on the new computer, use an organizational recovery process, or request certificate reissuance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If the old laptop no longer boots

  1. Create a forensic or full-disk image before experimenting.
  2. Repair or boot the original installation if possible.
  3. Sign in to the original account and perform a normal export.
  4. Ask the organization’s PKI administrator whether a backup, reissue, or key-recovery process exists.

For Microsoft AD CS, a Key Recovery Agent may recover an archived private key into a password-protected PKCS#12 file—but only if key archival was configured before issuance. It is not a universal recovery method. See Microsoft’s documentation on key recovery servers.

If a Windows password was reset, the profile was migrated, or the profile is damaged, treat the situation as a profile-recovery problem rather than assuming an administrator can export the key. Administrative access does not override every provider or hardware policy.

Secure-handling checklist

  • Use a long, unique export password.
  • Transfer the archive over an encrypted channel or protected removable media.
  • Never email the archive and its password together.
  • Store the archive in an access-controlled location.
  • Avoid extracting an unencrypted private key unless the destination requires it.
  • Delete temporary plaintext key files securely.
  • After testing the new installation, remove unnecessary copies from the old laptop and transfer media.
  • If the archive or password may have been exposed, ask the certificate issuer whether the certificate should be revoked and reissued.

Final verification

The migration is complete only when the new device or application can see the certificate and its associated private key, the certificate chain is accepted, the intended usage is permitted, and the actual operation works—for example, VPN login, TLS client authentication, mail decryption, document signing, or server authentication.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.