OpenSSH stores newly generated private keys in its own format by default. Most current SSH clients understand it, but some tools still expect a legacy PEM-encoded RSA private key.
One example is decrypting the initial Administrator password for a Windows EC2 instance. AWS documents this error when an OpenSSH-format RSA key is supplied:
Private key must begin with "-----BEGIN RSA PRIVATE KEY-----" and end with
"-----END RSA PRIVATE KEY-----"The key material does not need to change. The private key only needs to be rewritten in the format expected by the tool.
A private key grants access to every system that trusts its corresponding public key. Convert it on a trusted machine, do not paste it into an online converter, and remove temporary unencrypted copies as soon as they are no longer needed.
Identify the private-key format
Inspect only the first line of the private-key file:
head -n 1 ~/.ssh/my-keyCommon headers include:
| First line | Format |
|---|---|
-----BEGIN OPENSSH PRIVATE KEY----- |
OpenSSH private-key format |
-----BEGIN RSA PRIVATE KEY----- |
Traditional PEM-encoded RSA private key |
-----BEGIN PRIVATE KEY----- |
Unencrypted PKCS #8 PEM |
-----BEGIN ENCRYPTED PRIVATE KEY----- |
Encrypted PKCS #8 PEM |
The .pem filename extension is only a naming convention. The header inside the file identifies how the key is encoded.
This conversion is intended for an RSA private key. AWS requires RSA keys for Windows EC2 instances; converting an unsupported key type does not turn it into an RSA key.
Make a working copy
ssh-keygen rewrites the selected key file. Keep the original OpenSSH key and convert a copy:
cp ~/.ssh/my-key /tmp/my-key.pem
chmod 600 /tmp/my-key.pemUsing a copy also lets applications that support the newer OpenSSH format continue using the original key.
Convert the key and keep a passphrase
Run ssh-keygen with the passphrase-change operation and select PEM as the output format:
ssh-keygen -p -m PEM -f /tmp/my-key.pemThe options are:
-prewrites an existing private key through the passphrase-change operation.-m PEMselects the legacy PEM private-key format.-f /tmp/my-key.pemselects the working copy to update.
Enter the existing passphrase when prompted. You can then set a passphrase for the converted key.
Remove the passphrase when a tool requires it
Some import or decryption tools cannot read an encrypted private key. If the target tool explicitly requires an unencrypted key, set the new passphrase to an empty value:
ssh-keygen -p -N "" -m PEM -f /tmp/my-key.pemssh-keygen still prompts for the existing passphrase if the source key is protected. The resulting copy is not encrypted at rest, so restrict its permissions and lifetime carefully.
Leaving out -m PEM changes the passphrase but writes the key using OpenSSH's default private-key format. That does not solve a legacy PEM compatibility error.
Verify the result
Check the header without printing the rest of the private key:
head -n 1 /tmp/my-key.pemFor the RSA format expected by the EC2 Windows password workflow, it should report:
-----BEGIN RSA PRIVATE KEY-----Use the converted copy with the application that requires it. Once it is no longer needed, delete it securely according to the storage and backup behaviour of your operating system.
The ssh-keygen manual documents using -m PEM with -p to convert an existing private key. AWS also documents the OpenSSH-format error when decrypting a Windows EC2 password.