Export "Certificate in DER format" vs "Private key in DER format"

Hello | Last updated: Jan 21, 2016 11:12PM UTC

I'm confused by two options in "Proxy>>Options>>Export CA Cert". What is the difference between "Export Certificate in DER format" and "Export Private key in DER format"? 1. If I "Export Private key in DER format", what program do I use to open this file? 2. Isn't the private key also within the "Export Certificate in DER format" file?

PortSwigger Agent | Last updated: Jan 22, 2016 09:09AM UTC

Those two options do what they say: they separately export the certificate or the private key. You can use another DER-aware tool to do something with those files if you need to. Otherwise, you can reload them into Burp later, or another instance of Burp, using the import options in the same wizard.

Burp User | Last updated: Jan 22, 2016 02:16PM UTC

Do you mean that when I "Export Certificate in DER format", the output file doesn't include the private key? Also, why are they not combined into one file like the PKCS option?

PortSwigger Agent | Last updated: Jan 22, 2016 02:55PM UTC

That's right. As far as I know, the DER format doesn't allow for storing both together.

