An SSH key file can look unfamiliar without being invalid. Before converting it, check what kind of file it is—and whether the problem is actually the format.
Two terms often get mixed up: algorithm describes the cryptography, such as RSA or Ed25519; format describes how key data is stored in a file. The same algorithm can be represented in different formats, and different algorithms can use the same format.
Identify a key by its first line
For text-based key files, the opening line is usually the fastest clue:
| First line | What it usually indicates |
|---|---|
-----BEGIN OPENSSH PRIVATE KEY----- |
OpenSSH private key format |
-----BEGIN RSA PRIVATE KEY----- |
PEM-encoded PKCS#1 private key; RSA only |
-----BEGIN EC PRIVATE KEY----- |
PEM-encoded SEC1 private key; ECDSA only |
-----BEGIN PRIVATE KEY----- |
Unencrypted PEM-encoded PKCS#8 private key |
-----BEGIN ENCRYPTED PRIVATE KEY----- |
Encrypted PEM-encoded PKCS#8 private key |
PuTTY-User-Key-File-3: ... |
PuTTY PPK private key, version 3 |
ssh-ed25519 AAAA... |
OpenSSH public key, usually a single line |
---- BEGIN SSH2 PUBLIC KEY ---- |
RFC 4716 / SSH2 public key |
The dash count helps distinguish two easily confused headers: PEM-style headers have five hyphens with no space after them, while RFC 4716 uses four hyphens, a space, and then BEGIN.
A private key and its public key are different files. A public key commonly ends in .pub and is safe to install on a server; a private key should stay private. Don’t paste a private key into a website or share it to get help diagnosing its format.
PEM and PKCS#8 aren’t competing formats
“PEM” describes a text encoding: data is represented as Base64 between header and footer lines. It doesn’t, by itself, tell you the structure of the key inside.
PKCS#8 describes a private-key structure that can hold different algorithms. When it is PEM-encoded, its header is commonly BEGIN PRIVATE KEY or BEGIN ENCRYPTED PRIVATE KEY. By contrast, BEGIN RSA PRIVATE KEY usually indicates the RSA-specific PKCS#1 structure.
That distinction matters when a tool asks for “PEM.” It may mean PEM encoding generally, or it may expect a particular structure such as PKCS#1. Check the tool’s documentation rather than assuming those terms are interchangeable. For a closer look at the OpenSSH header and what it does—and doesn’t—tell you, see this explanation of BEGIN OPENSSH PRIVATE KEY.
Public keys have more than one representation
An OpenSSH public key is typically one line with the algorithm, encoded key data, and an optional comment:
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAI... laptop-key
The comment is a label for people; it isn’t used to authenticate the key. You’ll see this format in .pub files and in authorized_keys files.
Some tools instead request an SSH2 or RFC 4716 public key, which uses a multiline block. It represents public-key data in a different wrapper; it does not mean you need to generate a different cryptographic key.
You can export an OpenSSH public key to RFC 4716 format with ssh-keygen:
ssh-keygen -e -m RFC4716 -f ~/.ssh/id_ed25519.pub > id_ed25519_rfc4716.pub
To import an RFC 4716 public key into OpenSSH’s one-line format:
ssh-keygen -i -m RFC4716 -f imported_key.pub > imported_key_openssh.pub
Convert only when a tool requires it
If your key already works with your SSH client, a different-looking header is not a reason to change it. Conversion is useful when a particular application can’t read the current format, PuTTY needs a PPK file, or a service explicitly requires a particular public-key representation.
For supported private-key conversions, ssh-keygen -p -m can rewrite a key file. For example:
# Rewrite a supported private key as PEM
ssh-keygen -p -m PEM -f ~/.ssh/id_rsa
# Rewrite a supported private key as PKCS#8
ssh-keygen -p -m PKCS8 -f ~/.ssh/id_rsa
These commands operate on the file in place. Make a backup first, and confirm the chosen format works with the target application before replacing your only usable copy. Format and algorithm compatibility can vary, so don’t assume the same conversion will work for every key type.
PuTTY uses its own PPK format. Use PuTTYgen to import an OpenSSH private key and save it as .ppk; to convert back, use PuTTYgen’s Conversions → Export OpenSSH key. On Linux, the puttygen command can convert a PPK file to OpenSSH format:
puttygen key.ppk -O private-openssh -o id_rsa
PPK files also have versions. PuTTY 0.75 and later uses PPK v3 by default; older PuTTY releases can reject v3 files as too new. If you’re converting for an older installation, check its supported version in PuTTYgen’s format options.
After conversion, verify the key still works
A successful conversion should leave you with a key the intended client can read. Test it before deleting the backup or changing server access. Also check the private key’s permissions: converting the format does not change them. If OpenSSH rejects the file because it is accessible to other users, review the expected SSH key permissions.
The practical rule is simple: identify the file from its header, distinguish its container from its algorithm, and convert only to meet a real compatibility requirement.
I originally published a more detailed version of this guide on the SSHFlow blog.
I'm also building SSHFlow — an SSH client where every server gets its own workspace for terminals, SFTP, code, and databases.
Top comments (0)