.CRT file extension
To open .CRT files on Windows, double-click the .CRT file to open it in the Windows Certificate viewer (if file associations are set).
To open a .CRT file, use your operating system’s certificate viewer or import tool (it’s usually an X.509 certificate). If double-clicking doesn’t work, open it from the certificate/keychain management UI and import or view it there.
Last updated: June 11, 2026 · Reviewed by Julian Stricker
What “reviewed” means on this page
- Format fit: whether the “what is this file?” description matches common real-world use of the extension, including category, typical MIME types, and aliases.
- Opening paths: whether Windows / macOS / Linux steps read plausibly for current OS dialogs and default apps; we remove fantasy menus and unsafe shortcuts.
- Security framing: whether risk notes match the extension class (for example executables vs plain data) and whether affiliate wording does not contradict the security section.
- Sources and further reading: whether external links point to vendors, standards bodies, or other primary references where possible; we avoid inventing details we cannot ground.
- Limits: this is clarity and safety-messaging QA, not a guarantee that every statement is exhaustive or that every binary you download is harmless.
Full methodology in the Imprint — The Imprint also states where AI is used and what that does—and does not—replace.
Open on your device
Choose your operating system for a dedicated step-by-step opening guide.
How to open .CRT files
Use these platform-specific instructions to open .CRT files safely.
Windows
- Double-click the .CRT file to open it in the Windows Certificate viewer (if file associations are set).
- To install/import: open the certificate viewer and choose the install/import option (or use the appropriate certificate management UI for your scenario).
- If it still won’t open, try opening it as text to check whether it contains PEM headers like "-----BEGIN CERTIFICATE-----".
Mac
- Double-click the .CRT file; it commonly opens in Keychain Access for viewing/import.
- If it doesn’t, open Keychain Access and use the import function to add the certificate to the desired keychain.
- If needed, open in a text editor to confirm whether it is PEM (readable) or DER (binary).
Linux
- Open the .CRT file in a text editor first to see if it is PEM (it will show "BEGIN CERTIFICATE" blocks).
- If you need to trust it system-wide, import it using your distribution’s certificate trust mechanism (varies by distro) rather than simply opening it as a document.
- If you only need to inspect it, use a certificate-viewing tool available on your desktop environment or command-line tooling.
iOS
- iOS can handle certificates in some workflows, but viewing details and trust installation depends on how it is delivered; if it won’t open clearly, transfer the file to a desktop OS to inspect/import it.
Android
- Android certificate handling varies by device and version; if tapping the .CRT doesn’t present an install/view option, transfer it to a desktop OS to inspect/import it using certificate tools.
Security notes
- A .CRT is typically a certificate (public data), but importing/installing it changes what your device trusts; only import certificates from sources you trust to avoid man-in-the-middle risks.
- Be especially cautious with CA certificates: trusting a new CA can allow it to validate (and potentially intercept) TLS connections for many sites or services.
- Certificates are parsed by security libraries; avoid opening untrusted certificates in obscure or outdated tools, and prefer built-in OS certificate viewers/importers.
If you did not expect this file
This extension is usually plain data, text, or structured content—not a program by itself. The practical risk is social engineering (a scam attachment or misleading filename). For trusted senders you rarely need heavy-handed antivirus wording; use these tools when you want an extra check on unexpected downloads.
Avast offers free and premium antivirus software that protects against viruses, malware, ransomware, and phishing. Scan files before opening them to ensure safety.
NortonNorton 360 delivers comprehensive antivirus protection, VPN, and identity theft monitoring. Scan files for threats before opening to keep your device secure.
We may earn a commission when you use affiliate links. This supports our free file extension guides.
Can't open this file?
These are the most common causes and fixes when .CRT files fail to open.
Common reasons
- The .CRT opens as unreadable characters
- Import/installation fails
- The certificate is rejected as expired or not yet valid
- Wrong file type: expecting a certificate but it’s something else
Fix steps
- Try opening it with the OS certificate viewer/import tool instead of a text editor.
- If you need a text form for copy/paste, obtain a PEM version from the issuer/export process rather than renaming the file.
OS-specific troubleshooting
What is a .CRT file?
.CRT is widely used to store X.509 certificates used in public key infrastructures (PKI), including TLS server certificates and CA certificates. The certificate structure is defined by the Internet PKIX profile (X.509/PKIX), and the file is commonly encoded either as PEM (Base64 text with BEGIN/END markers) or DER (binary).
Background
X.509 certificates bind an identity (like a domain name, organization, or device) to a public key and are a foundation of HTTPS/TLS and many authentication systems. The Internet PKIX profile describes how certificates are represented and validated in common Internet use.
Common MIME types: application/x-x509-ca-cert
Further reading
Authoritative resources for more details on the .CRT format.
- RFC 5280: Internet X.509 Public Key Infrastructure Certificate and CRL Profile
- RFC 2585: application/pkix-cert registration (Internet X.509 PKI Operational Protocols)
- RFC 8894 (PDF): application/x-x509-ca-cert usage for CA certificates
- IANA Media Types Registry (official list of registered media types)
- X.509 (background and common extensions like .cer/.crt)
- Microsoft Learn: Certificate Manager (HoloLens) – supports .cer and .crt
Common .CRT issues
The .CRT opens as unreadable characters
This usually means the certificate is in DER (binary) encoding rather than PEM (text).
- Try opening it with the OS certificate viewer/import tool instead of a text editor.
- If you need a text form for copy/paste, obtain a PEM version from the issuer/export process rather than renaming the file.
Import/installation fails
The certificate may be corrupted, incomplete, not valid for the intended use, or missing required intermediate certificates in the chain.
- Re-download or re-export the certificate to ensure it is complete and unmodified.
- Verify you also have any required intermediate/CA certificates needed to build a valid trust chain.
The certificate is rejected as expired or not yet valid
X.509 certificates have validity dates, and systems will reject certificates outside the valid time window.
- Check the certificate validity dates in the certificate viewer.
- Confirm the device/system clock is correct; then obtain an updated/reissued certificate if it is genuinely expired.
Wrong file type: expecting a certificate but it’s something else
Some workflows use .crt loosely, but the most common meaning is an X.509 certificate; if the content doesn’t match, your tool may refuse it.
- Open the file in a text editor and look for PEM markers ("BEGIN CERTIFICATE").
- Confirm with the sender/system documentation whether you were supposed to receive a certificate, a CA bundle, or a different artifact.
FAQ
Is a .CRT file a certificate or a key?
Most commonly it is an X.509 certificate (public). Private keys are usually stored separately (often with different extensions) and should not be shared.
What’s the difference between .CRT and .CER?
In practice they are both commonly used for X.509 certificates; the extension alone doesn’t guarantee the encoding. The content may be PEM (text) or DER (binary).
Can I convert a .CRT by renaming it to .PEM or .DER?
No. Renaming only changes the filename. If you need a different encoding, you must export/convert the certificate using certificate tooling.
Which MIME type is used for .CRT downloads?
Common registered media types for X.509 certificates include application/pkix-cert, and .crt is also used in practice with application/x-x509-ca-cert (especially for CA certificates).
Similar file extensions
Compare related formats in the same category to find the right tool faster.
- .pfx - Personal Information Exchange (PFX)
- .pem - PEM-encoded Certificate
- .p12 - PKCS#12 Certificate Bundle
- .csr - PKCS #10 Certificate Signing Request
- .der - DER-encoded X.509 Certificate
- .p7b - PKCS #7 Certificate Bundle (P7B)
- .ac - X.509 Attribute Certificate
- .p7s - PKCS #7 / S/MIME Digital Signature (detached signature)