Certificate File Import

Last Updated : Aug 30, 2026 |
Prolog information
File Content
Identity Certificate Import Command
Trusted Certificate Import Command
Signing Certificate Import Command
Notes
DER
DER: 1 certificate
No – attempt rejected with ‘Invalid certificate format (DER)’
Yes – attempt accepted with ‘N certificate(s) imported into Trusted Certificate Store’
No – attempt rejected with ‘Invalid certificate format (DER)’
DER: Any other content
No – attempt rejected with ‘Invalid content (DER)’
No – attempt rejected with ‘Invalid content (DER)’
No – attempt rejected with ‘Invalid content (DER)’
PKCS#12
PKCS#12: 1 certificate + private key
Yes – attempt accepted with ‘Certificate import successful’
Certificate/key imported as ID certificate
No – p12/pfx should not be offered for file selection
Yes – attempt accepted with ‘Certificate import successful’
PKCS#12: 1 certificate + private key, 1 or more other certificates
Yes – attempt accepted with ‘Certificate import successful’
Certificate/key imported as ID certificate
Other certificates imported into TCS with ‘N certificate(s) imported into Trusted Certificate Store’
No – p12/pfx should not be offered for file selection
Yes – attempt accepted with ‘Certificate import successful’
Certificate/key imported as signing certificate
Other certificates ignored
At least 20 certificates supported in the same file
PKCS#12: Any other content
No – attempt rejected with ‘Invalid content (PKCS#12)’
No – p12/pfx should not be offered for file selection
No – attempt rejected with ‘Invalid content (PKCS#12)’
PEM: 1 Certificate
No – attempt rejected with ‘Invalid certificate format (PEM – no private key)’
Yes – attempt accepted with ‘N certificate(s) imported into Trusted Certificate Store’
No – attempt rejected with ‘Invalid certificate format (PEM – no private key)’
Certificate can be encrypted on unencrypted
PEM
PEM: N Certificate
No – attempt rejected with ‘Invalid certificate format (PEM – no private key)’
Yes – attempt accepted with ‘N certificate(s) imported into Trusted Certificate Store’
No – attempt rejected with ‘Invalid certificate format (PEM – no private key)’
At least 20 certificates supported in the same file
Certificate can be encrypted on unencrypted
PEM: 1 Certificate + private key
Yes – attempt accepted with ‘Certificate import successful’
Certificate/key imported as ID certificate
No – attempt rejected with ‘Invalid certificate format (PEM)’
Yes – attempt accepted with ‘Certificate import successful’
Certificate/key imported as signing certificate
Certificate or Key can be encrypted on unencrypted
PEM: 1 Certificate + private key, 1 or more other certificates.
Private key must be before or after the first certificate
Yes – attempt accepted with ‘Certificate import successful’
Certificate/key imported as ID certificate.
Other certificates imported into TCS with ‘N certificate(s) imported into Trusted Certificate Store’
Yes – attempt accepted with ‘N certificate(s) imported into Trusted Certificate Store’
First certificate and private key ignored
Yes – attempt accepted with ‘Certificate import successful’
Certificate/key imported as signing certificate
Other certificates ignored
Private key must be before or after the first certificate
Certificate or Key can be encrypted on unencrypted
PEM: Any other content
No – attempt rejected with ‘Invalid content (PEM)’
No – attempt rejected with ‘Invalid content (PEM)’
No – attempt rejected with ‘Invalid content (PEM)’
Option to include more detail of the rejection cause.e.g. ‘Cannot detect Identity Certificate’, ‘Too many private keys’, ‘Unrecognized header’ etc.