“Key values mismatch” in Apache or nginx, or a panel refusing to install a certificate, almost always means the certificate was issued for a different private key. Paste any two or three of the certificate, private key and CSR to find out which ones belong together.
Private key safety. The comparison runs in your browser and nothing is sent to srvScripts. This page loads no analytics, ads or other third-party scripts, and your browser is told to block connections to every other site while it is open. If your policy does not allow pasting keys into any web page, compare them offline instead; the two hashes match when the key belongs to the certificate:
openssl x509 -noout -pubkey -in certificate.crt | openssl sha256
openssl pkey -pubout -in private.key | openssl sha256
# a CSR as well:
openssl req -noout -pubkey -in request.csr | openssl sha256Table of Contents
How the match works
Every certificate and CSR embeds a public key, and every private key contains or implies its public key. The tool extracts the RSA modulus or the EC public point from each item and compares them; if they are identical the items form a pair. RSA keys in PKCS#1 (BEGIN RSA PRIVATE KEY) and PKCS#8 (BEGIN PRIVATE KEY) formats and EC keys in SEC1 or PKCS#8 are supported.
Encrypted keys (BEGIN ENCRYPTED PRIVATE KEY) must be decrypted first. Work on a copy: openssl pkey -in encrypted.key -out plain.key
Fixing a mismatch
Find the key that was generated with the CSR: in cPanel it is listed under SSL/TLS → Private Keys with the same date; in DirectAdmin and on plain servers look in the folder where the CSR was created. If the key is lost, generate a new key and CSR and ask the CA to reissue; reissues are free with every major CA.
Certificate key matcher at a glance



Official documentation: Let’s Encrypt documentation, cPanel & WHM documentation, AlmaLinux wiki.
Related guides: KernelCare on cPanel and DirectAdmin servers: setup, verification and rollback · Replacing cxs: malware scanning with LMD (maldet), ClamAV and ImunifyAV on hosting servers · Incident response after a cPanel root-escalation CVE: rotating keys, hunting .sorry, auditing sessions.
Frequently asked questions
Is it safe to paste a private key here?
The comparison runs in JavaScript in your browser and nothing is sent to our server. For production keys you can also use the OpenSSL commands shown in the result and compare the hashes.
Does it support ECDSA certificates?
Yes, for P-256, P-384 and P-521 keys, as long as the private key file includes its public key, which OpenSSL does by default.
What if only the intermediate is wrong?
A key match only checks the leaf certificate. Use the SSL certificate checker on the live site to confirm the intermediate chain.