Browse by section

Web Design & Dev 日本語

Convert pem and ppk on a Mac with PuTTYgen

SSH private keys come in two shapes you are likely to meet: the OpenSSH format, usually saved as .pem, and PuTTY’s own .ppk.

The short answer: on a Mac, install PuTTYgen with brew install putty, then use puttygen key.pem -o key.ppk to go from .pem to .ppk and puttygen key.ppk -O private-openssh -o key.pem to go back.

There is one catch. Since PuTTY 0.75, PuTTYgen writes PPK version 3 by default, and older tools reject it with “PuTTY key format too new”. This article includes the way around that.

Sponsored

Which format do you actually need?

The short answer: the ssh command on macOS and Linux reads OpenSSH format directly. You only need .ppk for PuTTY or WinSCP on Windows.

Format Used by On a Mac
.pem (OpenSSH format) The ssh command, AWS EC2 key pairs, most CI tools Works as is
.ppk (PuTTY format) PuTTY, WinSCP, some FileZilla setups Needs conversion

The conversion comes up when a handover leaves you with only a .ppk, or when you have to hand a .ppk to someone on Windows.

How do you install PuTTYgen on a Mac?

The short answer: use Homebrew. The PuTTYgen on the PuTTY website is a Windows GUI application and will not run on macOS.

brew install putty
puttygen --version

If brew is not available yet, set up Homebrew first; the steps are in installing Homebrew and Vim on a Mac.

The putty formula includes plink and pscp alongside puttygen. Note that pscp conflicts with the pssh package, so if you have both you will need brew link to switch between them.

Sponsored

Converting .pem to .ppk

The short answer: run puttygen source.pem -o output.ppk. PPK is the default output format, so no type flag is needed.

puttygen key.pem -o key.ppk

Replace key.pem with your filename. The original is left untouched and a new key.ppk is created.

If the source key has a passphrase, you will be prompted for it.

Fixing “PuTTY key format too new”

The short answer: PuTTYgen from PuTTY 0.75 (released 2021) writes PPK version 3 by default, and older PuTTY, WinSCP and some CI tools cannot read it.

The error looks like: Unable to load key file "key.ppk" (PuTTY key format too new). Write version 2 instead.

puttygen key.pem -O private --ppk-param version=2 -o key.ppk

PPK version 3 uses the Argon2 key derivation function to make passphrase brute-forcing harder, and moves the MAC hash from SHA-1 to SHA-256. If the receiving tool supports version 3, leave it there. Drop to version 2 only when something actually fails to read it.

Converting .ppk to .pem

The short answer: run puttygen source.ppk -O private-openssh -o output.pem. The -O private-openssh flag is the important part.

puttygen key.ppk -O private-openssh -o key.pem

Omit -O and you get a PPK-format file that merely has a .pem extension. When ssh refuses to read the result, check this first.

For the newer OpenSSH key format, use private-openssh-new.

puttygen key.ppk -O private-openssh-new -o key.pem

Sponsored

Set the converted key to permission 400

The short answer: a freshly converted key can be readable by other users, and ssh will refuse to connect. Run chmod 400.

chmod 400 key.pem
ssh -i key.pem user@server-address

With loose permissions you get this and the connection stops.

WARNING: UNPROTECTED PRIVATE KEY FILE!
Permissions 0644 for 'key.pem' are too open.

Do not share the converted key

The short answer: a converted private key is still a private key. Do not send it over chat or email.

.pem and .ppk are different containers holding the same secret. Changing the format changes nothing about how sensitive it is.

What you normally hand to someone else is the public key. You can extract it like this.

puttygen key.ppk -O public-openssh -o key.pub

If you are setting up key authentication in order to deploy, creating a password-protected ZIP on macOS covers a related question of how to move sensitive files around safely.