(1)将.pfx格式的证书转换为.pem文件格式: openssl pkcs12 -in xxx.pfx -nodes -out server.pem (2)从.pem文件中导出私钥server.key: openssl rsa -in server.pem -out server.key (3)从.pem文件中导出证书server.crt openssl x509 -in server.pem -out server.crt