If you have a key stored in a single “.pem” file, you must split it into two files before importing.

1,213 views
Skip to first unread message

Noel Dennis

unread,
Jul 24, 2017, 3:50:52 PM7/24/17
to chromium-hterm
Firstly, Thank You for your awesome support of this group.  What a pleasure to post a (stupid) question and receive an intelligent answer so quickly.

So I have a .pem file which has as the first line:

-----BEGIN RSA PRIVATE KEY-----

and a last line of:

-----END RSA PRIVATE KEY-----

I believe I see what is the PRIVATE key, but where is the PUB key?


Mike Frysinger

unread,
Jul 24, 2017, 4:29:08 PM7/24/17
to Noel Dennis, chromium-hterm
i think you want this:

$ openssl rsa -in private.pem -outform PEM -pubout -out public.pem
-mike

--
You received this message because you are subscribed to the Google Groups "chromium-hterm" group.
To view this discussion on the web visit https://groups.google.com/a/chromium.org/d/msgid/chromium-hterm/013c65e6-9b98-4726-81ea-7186d21a9014%40chromium.org.

Noel Dennis

unread,
Jul 24, 2017, 4:58:53 PM7/24/17
to chromium-hterm, noel...@gmail.com
Thank you!  But....  This requires a "command line" on my Chromebox.  A "command line" is what I am trying to find.  I thought that maybe "Secure Shell" would allow me to open the "command line" for the server.  Guess I am out of my depth and need to go back to "school"....

What I mean is the article you referenced refers to running "openssl", but where?  Where is the "command line"?  

Guess I am looking for a "Putty" equivalent to run on Chromebox.

Mike Frysinger

unread,
Jul 24, 2017, 5:05:01 PM7/24/17
to chromium-hterm
i'm not aware of a method of splitting the pub key out of the certificate only under CrOS.  the commands i suggested assume you have access to a Linux system somewhere already.

there are probably web services out there that let you upload a cert and they'll split out/send back the pub key part.  i would strongly suggest not using them though as you shouldn't be sharing your priv key with random sites :).

Secure Shell's key management is a bit weak currently.  this is a situation where we should allow people to import a cert and we just DTRT for you.  but we don't today.
-mike

Reply all
Reply to author
Forward
0 new messages