IBMDO YOU?Hi, I'm MBO!

Settings

Make the site feel at home on your screen.

Theme

Loading your theme preference.

Keyboard shortcuts

Open search from anywhere, then move through the results without leaving the keyboard.

Open settings
Ctrl,or⌘,
Open search
CtrlKor⌘K
Select a search result
↑↓
Open the selected result
Enter
Close an open dialog
Esc

Linux

Convert an OpenSSH private key to PEM format

Identify an OpenSSH private key and convert an RSA key to legacy PEM format for tools that cannot read the newer OpenSSH format.

Solved — confirmed solution

OpenSSH stores newly generated private keys in its own format by default. Most current SSH clients understand it, but some tools still expect a legacy PEM-encoded RSA private key.

One example is decrypting the initial Administrator password for a Windows EC2 instance. AWS documents this error when an OpenSSH-format RSA key is supplied:

Private key must begin with "-----BEGIN RSA PRIVATE KEY-----" and end with
"-----END RSA PRIVATE KEY-----"

The key material does not need to change. The private key only needs to be rewritten in the format expected by the tool.

A private key grants access to every system that trusts its corresponding public key. Convert it on a trusted machine, do not paste it into an online converter, and remove temporary unencrypted copies as soon as they are no longer needed.

Identify the private-key format

Inspect only the first line of the private-key file:

head -n 1 ~/.ssh/my-key

Common headers include:

First line Format
-----BEGIN OPENSSH PRIVATE KEY----- OpenSSH private-key format
-----BEGIN RSA PRIVATE KEY----- Traditional PEM-encoded RSA private key
-----BEGIN PRIVATE KEY----- Unencrypted PKCS #8 PEM
-----BEGIN ENCRYPTED PRIVATE KEY----- Encrypted PKCS #8 PEM

The .pem filename extension is only a naming convention. The header inside the file identifies how the key is encoded.

This conversion is intended for an RSA private key. AWS requires RSA keys for Windows EC2 instances; converting an unsupported key type does not turn it into an RSA key.

Make a working copy

ssh-keygen rewrites the selected key file. Keep the original OpenSSH key and convert a copy:

cp ~/.ssh/my-key /tmp/my-key.pem
chmod 600 /tmp/my-key.pem

Using a copy also lets applications that support the newer OpenSSH format continue using the original key.

Convert the key and keep a passphrase

Run ssh-keygen with the passphrase-change operation and select PEM as the output format:

ssh-keygen -p -m PEM -f /tmp/my-key.pem

The options are:

  • -p rewrites an existing private key through the passphrase-change operation.
  • -m PEM selects the legacy PEM private-key format.
  • -f /tmp/my-key.pem selects the working copy to update.

Enter the existing passphrase when prompted. You can then set a passphrase for the converted key.

Remove the passphrase when a tool requires it

Some import or decryption tools cannot read an encrypted private key. If the target tool explicitly requires an unencrypted key, set the new passphrase to an empty value:

ssh-keygen -p -N "" -m PEM -f /tmp/my-key.pem

ssh-keygen still prompts for the existing passphrase if the source key is protected. The resulting copy is not encrypted at rest, so restrict its permissions and lifetime carefully.

Leaving out -m PEM changes the passphrase but writes the key using OpenSSH's default private-key format. That does not solve a legacy PEM compatibility error.

Verify the result

Check the header without printing the rest of the private key:

head -n 1 /tmp/my-key.pem

For the RSA format expected by the EC2 Windows password workflow, it should report:

-----BEGIN RSA PRIVATE KEY-----

Use the converted copy with the application that requires it. Once it is no longer needed, delete it securely according to the storage and backup behaviour of your operating system.

The ssh-keygen manual documents using -m PEM with -p to convert an existing private key. AWS also documents the OpenSSH-format error when decrypting a Windows EC2 password.

Find the fix

Search articles

Esc

Search titles, technical terms or error codes.