OpenSSL Error: 'unable to load Private Key' — Cause, Fix, and Troubleshooting Guide
Fix OpenSSL 'unable to load Private Key' (PEM routines / no start line / bad decrypt): wrong format, encrypted key, corrupt PEM, or a cert-key mismatch.
- #security
- #hardening
- #troubleshooting
- #linux
- #openssl
Stuck on this DevOps Security & Hardening error? Get the free incident triage checklist
A one-page PDF — the exact steps to isolate, fix, and verify a production error like this one. No spam, unsubscribe anytime.
What this error means
OpenSSL could not parse the file you gave it as a private key. The bytes are not a valid key in the expected encoding, the key is encrypted and the passphrase was wrong, or the file is actually a certificate/CSR rather than a key.
unable to load Private Key
140234...:error:0909006C:PEM routines:get_name:no start line:../crypto/pem/pem_lib.c:745:Expecting: ANY PRIVATE KEY
Related lines pointing at the same class of problem:
error:0906D06C:PEM routines:PEM_read_bio:no start line
error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt (wrong passphrase)
no start line means OpenSSL never found a -----BEGIN ... PRIVATE KEY----- header where it expected one.
Symptoms at the client
openssl rsa -in key.pem -checkoropenssl pkey -in key.pemfails to load the file.- nginx/Apache/HAProxy refuses to start, logging that it cannot load the private key.
- Building a combined PEM or PKCS#12 bundle fails at the key step.
- The certificate loads fine but the key does not.
Trust and cipher causes
- Wrong file. You passed the certificate, CSR, or public key instead of the private key.
- Wrong format. The key is DER (binary) or PKCS#12/PFX, but the command expects PEM.
- Encrypted key, wrong/missing passphrase. The key is password-protected and the passphrase is incorrect (
bad decrypt). - Corrupt or truncated PEM. A copy-paste dropped the header/footer or altered whitespace/line endings (CRLF).
- Mismatched key and certificate. The key is valid but does not correspond to the cert you are pairing it with.
Inspecting the TLS handshake
# What does the file actually contain?
head -1 key.pem
file key.pem
openssl asn1parse -in key.pem 2>&1 | head # gibberish/errors => not the key you think
# Try to load it explicitly as a private key
openssl pkey -in key.pem -noout 2>&1
# If it is DER (binary), this succeeds where PEM parsing failed:
openssl pkey -inform DER -in key.der -noout 2>&1
A first line that is -----BEGIN CERTIFICATE----- (not PRIVATE KEY) means you have the wrong file. A bad decrypt means the format is fine but the passphrase is wrong.
The fix
1. Confirm you have the key, not the cert. The header must read PRIVATE KEY (or RSA/EC PRIVATE KEY). If not, locate the real key file.
2. Convert DER to PEM if the encoding is binary:
openssl pkey -inform DER -in key.der -out key.pem
3. Extract the key from a PKCS#12 / PFX bundle:
openssl pkcs12 -in bundle.pfx -nocerts -nodes -out key.pem
4. Supply the correct passphrase (or strip it for a service that cannot prompt):
openssl rsa -in enc-key.pem -out plain-key.pem # prompts; writes an unencrypted key
5. Verify the key matches the certificate before deploying — the moduli must be identical:
openssl x509 -noout -modulus -in cert.pem | openssl md5
openssl rsa -noout -modulus -in key.pem | openssl md5
# the two hashes must match
Certificate lifecycle
- An unencrypted private key on disk must be
chmod 600, owned by the service user — treat it as a secret. - Beware CRLF line endings from Windows editors; they corrupt PEM parsing. Normalize with
dos2unix. - Do not store passphrases in service configs in cleartext; if the service cannot prompt, use a systemd credential or key-management integration.
- Stripping the passphrase trades convenience for exposure — only do it for keys protected by strict file permissions and access controls.
Related TLS errors
- x509 ‘certificate has expired’ Error Guide
- TLS Handshake Failure ‘no shared cipher’ Error Guide
- ‘unable to get local issuer certificate’ Error Guide
Fixed it? Get 500 DevOps Security & Hardening & DevOps AI prompts — free
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.
Stuck on this? Start guided troubleshooting
Open an interactive diagnostic session with this error already loaded. Work a step-by-step plan, record what each check returns, land on a root cause, and export a clean incident summary — no account needed to start.
Did this fix your issue?
Solved it a different way?
Share the fix that worked for you — reviewed, then published to help the next engineer.
That looks like it may contain a secret (key, token, password, or connection string). Please remove it — a note with a detected secret can’t be published.
Thanks — that helps. Published notes appear after a quick review.
Trending errors this week
The error guides other engineers are actually reading right now.
- 1mount: wrong fs type, bad option, bad superblock
- 2Docker 'failed to set up container networking': Fix the Bridge and IP Pool
- 3Docker 'failed to create shim task': How to Fix the containerd Runtime Error
- 4Transport endpoint is not connected
- 5modprobe: FATAL: Module not found
- 6mount: wrong fs type, bad option, bad superblock
Get 500 Battle-Tested DevOps AI Prompts — Free
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.