Emergency server help: get in touch

Certificate Key Matcher: Free Safe Cert and Key Check

Check whether an SSL certificate, private key and CSR belong together by comparing their public keys in your browser. The private key never leaves your computer.

Status
Live
Last updated
October 3, 2026

“Key values mismatch” in Apache or nginx, or a panel refusing to install a certificate, almost always means the certificate was issued for a different private key. Paste any two or three of the certificate, private key and CSR to find out which ones belong together.

Private key safety. The comparison runs in your browser and nothing is sent to srvScripts. This page loads no analytics, ads or other third-party scripts, and your browser is told to block connections to every other site while it is open. If your policy does not allow pasting keys into any web page, compare them offline instead; the two hashes match when the key belongs to the certificate:

openssl x509 -noout -pubkey -in certificate.crt | openssl sha256
openssl pkey -pubout -in private.key | openssl sha256
# a CSR as well:
openssl req -noout -pubkey -in request.csr | openssl sha256

How the match works

Every certificate and CSR embeds a public key, and every private key contains or implies its public key. The tool extracts the RSA modulus or the EC public point from each item and compares them; if they are identical the items form a pair. RSA keys in PKCS#1 (BEGIN RSA PRIVATE KEY) and PKCS#8 (BEGIN PRIVATE KEY) formats and EC keys in SEC1 or PKCS#8 are supported.

Encrypted keys (BEGIN ENCRYPTED PRIVATE KEY) must be decrypted first. Work on a copy: openssl pkey -in encrypted.key -out plain.key

Fixing a mismatch

Find the key that was generated with the CSR: in cPanel it is listed under SSL/TLS → Private Keys with the same date; in DirectAdmin and on plain servers look in the folder where the CSR was created. If the key is lost, generate a new key and CSR and ask the CA to reissue; reissues are free with every major CA.

Certificate key matcher at a glance

Certificate Key Matcher summary card: "Key values mismatch" in Apache or nginx, or a panel refusing to install a certificate, almost always means the…
In short: “Key values mismatch” in Apache or nginx, or a panel refusing to install a certificate, almost always means the certificate was issued for a different private key.
Certificate Key Matcher sections: How the match works and Fixing a mismatch
Covers: How the match works and Fixing a mismatch.
Certificate Key Matcher questions answered: Is it safe to paste a private key here? Does it support ECDSA certificates?
Answers: Is it safe to paste a private key here? Does it support ECDSA certificates?

Official documentation: Let’s Encrypt documentation, cPanel & WHM documentation, AlmaLinux wiki.

Related guides: KernelCare on cPanel and DirectAdmin servers: setup, verification and rollback · Replacing cxs: malware scanning with LMD (maldet), ClamAV and ImunifyAV on hosting servers · Incident response after a cPanel root-escalation CVE: rotating keys, hunting .sorry, auditing sessions.

Frequently asked questions

Is it safe to paste a private key here?

The comparison runs in JavaScript in your browser and nothing is sent to our server. For production keys you can also use the OpenSSL commands shown in the result and compare the hashes.

Does it support ECDSA certificates?

Yes, for P-256, P-384 and P-521 keys, as long as the private key file includes its public key, which OpenSSL does by default.

What if only the intermediate is wrong?

A key match only checks the leaf certificate. Use the SSL certificate checker on the live site to confirm the intermediate chain.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.