Sorry for the long title, this week by special request, I’m going to talk about a PowerShell script I created for someone. Working with Windows Certificate Services often means dealing with certificates stored in the Windows Certificate Store. However, not every application can consume certificates directly from that store. Some applications require separate PEM files containing the certificate and its private key.
To make this process easier, I created Export-CertificateToPem.ps1, a PowerShell script that exports certificates and their associated private keys from the Windows Certificate Store into PEM format.
The script is currently at version 1.3.0 and supports RSA, ECDSA, and ECDH private keys.
More than just exporting a certificate
The script retrieves a certificate from Cert:\LocalMachine\My using its thumbprint and exports both the certificate and its associated private key.
Private keys are exported using the PKCS#8 format. By default, the private key is encrypted using PBES2 with AES-256-CBC and PBKDF2-HMAC-SHA256. Unencrypted export is also available when explicitly requested.
An important part of the implementation is validation. After exporting the private key, the script imports it again and compares its public key with both the original private key and the certificate. The generated files are also read back from disk and verified before being published. This helps ensure that the resulting PEM files contain the correct certificate and matching private key.
Using the script
The script requires Windows and PowerShell 7.4 or later. It automatically requests administrator elevation when necessary. For example, to export a certificate with an encrypted private key:
.\Export-CertificateToPem.ps1 `
-Thumbprint "YOUR_CERTIFICATE_THUMBPRINT" `
-OutputPath "C:\Temp\Certificates" `
-Force `
-VerboseThe script generates two files:
certificate.pem– the certificate in PEM format.privatekey.pem– the corresponding private key in PKCS#8 PEM format.
Script parameters
The script provides four parameters to control certificate selection, output location, private key encryption, and file overwriting.
| Parameter | Required | Description |
|---|---|---|
-Thumbprint | Yes | Specifies the thumbprint of the certificate to export from Cert:\LocalMachine\My. |
-OutputPath | No | Specifies the directory where the PEM files will be saved. Defaults to the current user’s Desktop. |
-NoEncryption | No | Exports the private key without password protection. By default, private keys are encrypted using AES-256-CBC. |
-Force | No | Allows existing certificate.pem and privatekey.pem files to be overwritten. |
As the script uses [CmdletBinding()], standard PowerShell common parameters such as -Verbose are also available. Using -Verbose provides additional information about certificate detection, private key export, validation, and file operations.
Example: Exporting an unencrypted private key
.\Export-CertificateToPem.ps1 `
-Thumbprint "YOUR_CERTIFICATE_THUMBPRINT" `
-OutputPath "C:\Temp\Certificates" `
-NoEncryption `
-Force `
-VerboseSecurity consideration! The -NoEncryption parameter should only be used when an application specifically requires an unencrypted private key. Although the script restricts access to the generated private key file, password-protected PKCS#8 export remains the recommended default.
What about Post-Quantum Cryptography?
During development, I also experimented with adding ML-DSA support. Using .NET 10, I successfully generated and exported ML-DSA-65 private keys. However, obtaining an ML-DSA certificate and accessing its private key through the traditional Windows certificate enrollment interfaces proved more challenging. Although Windows Server 2025 recognizes ML-DSA algorithms, my tests did not result in successful ML-DSA certificate enrollment through CertEnroll and AD CS.
For now, I have therefore kept the script focused on RSA and elliptic-curve cryptography, where the complete export and verification process can be used with existing Windows certificates.
It is an interesting reminder that supporting a cryptographic algorithm does not automatically mean the entire PKI ecosystem supports it.
In conclusion
Exporting certificates to PEM is straightforward in principle, but handling private keys securely and verifying the results deserves additional attention. This script brings those steps together into a reusable PowerShell workflow. The script is available on my GitHub repository:
Export-CertificateToPem.ps1 — GitHub
As Windows PKI evolves toward post-quantum cryptography, I intend to revisit ML-DSA support when the necessary enrollment and private-key interfaces become available.
Until next time!
Leave a Reply