PuTTY saves private keys in its own .ppk (PuTTY Private Key) format, while OpenSSH and many other tools use OpenSSH-style private key files. A file extension is only a label: what matters is the actual format your destination expects. People often call these files .pem (PEM stands for Privacy Enhanced Mail), but naming a file .pem does not make it PEM. PuTTYgen's documentation explains that modern OpenSSH has two private-key formats, an older PEM-style format and a newer native OpenSSH format, and that PuTTYgen picks between them depending on the key type. Check which format your cloud provider, server or tool asks for before you convert. Below are the steps for both directions of conversion.
.pem to .ppk Conversion
To convert a .pem file to a .ppk format, you need to use PuTTYgen, a key generator tool for PuTTY. PuTTYgen can import SSH-2 private keys in OpenSSH's format and in ssh.com's format. Here's how you do it:
- Open PuTTYgen: If you don't have PuTTYgen, you'll need to download and install PuTTY, which includes PuTTYgen.
- Load the .pem File: Start PuTTYgen, then click "Load" (or use Conversions, then Import key). The file picker may list only
.ppkfiles, so choose the option that shows all files if you cannot see your.pemfile. Select your key file. PuTTYgen may show a message that the key is not a PuTTY native key; that is expected for a key you are importing. - Enter the Passphrase (if applicable): If a passphrase protects your key file, enter it when prompted.
- Save the Private Key in .ppk Format: Once the key is loaded, click on "Save private key." If the key has no passphrase, PuTTYgen warns you before saving it. We recommend setting a passphrase unless you have a specific reason not to. Save the file with a
.ppkextension.
.ppk to .pem Conversion
To convert a .ppk file to an OpenSSH-format private key (often saved with a .pem name), you can use PuTTYgen for Windows or the putty-tools package on Linux. Which file format you get depends on the key type and the option you choose, not on the file name.
Windows
- Open PuTTYgen and load your
.ppkfile by clicking "Load" and selecting the.ppkfile. - Once loaded, go to "Conversions" in the menu and select "Export OpenSSH key". If your
.ppkfile has a passphrase, you'll need to enter it. Per the PuTTYgen documentation, this option automatically chooses the oldest OpenSSH format that supports the key type, for compatibility with older OpenSSH versions, and uses the newer OpenSSH format for key types such as Ed25519, where it is the only option. "Export OpenSSH key (force new file format)" forces the newer format for RSA, DSA and ECDSA keys too, but it needs OpenSSH 6.5 or newer. - Save the Key: Name your file and save it. Many services expect a
.pemname, but the name does not change the format. If your destination requires a specific format, check that its documentation matches what PuTTYgen produced.
Linux (Using putty-tools)
- Install
putty-tools: If not already installed, you can typically install it using your distribution's package manager. For Debian-based systems, you would use:sudo apt-get install putty-tools - Convert the Key: Use the command
puttygen yourkey.ppk -O private-openssh -o yourkey.pem, replacingyourkey.ppkwith your.ppkfile name andyourkey.pemwith the desired output file name. In theputtygenmanual page,private-opensshsaves an SSH-2 private key in OpenSSH's oldest available format for backward compatibility, andprivate-openssh-newforces the newer OpenSSH format even for RSA, DSA and ECDSA keys. We have not run these commands on every distribution or PuTTY version, so test the result with your own tool before relying on it. - Set Correct Permissions: For your '.pem' file to be recognized as secure by SSH, it's important to set the correct permissions. You can do this with the command
chmod 600 yourkey.pem.
This covers the basic process of converting between PuTTY's .ppk format and OpenSSH-style key files. Remember, the security of your private key is paramount, so ensure it's always kept secure and never shared.



