# Error adding cert, Invalid private key

**URL:** <https://community.letsencrypt.org/t/error-adding-cert-invalid-private-key/5167>\
**Category:** Uncategorized\
**Created:** [December 3, 2015, 10:45pm UTC](https://community.letsencrypt.org/t/error-adding-cert-invalid-private-key/5167 "2015-12-03T22:45:57Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ksolomon](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ksolomon/32/2524_2.png) [@ksolomon](https://community.letsencrypt.org/u/ksolomon)\
**Post date:** [December 3, 2015, 10:45pm UTC](https://community.letsencrypt.org/t/error-adding-cert-invalid-private-key/5167/1 "2015-12-03T22:45:57Z")

</div>

I generated a cert (manual, cert-only) for my personal sited hosted with Dreamhost. Generation was successful, however, when I tried to install it I got an error that said my private key was invalid. Just for the record, I also had to change the BEGIN and END lines, since DH’s setup looks for the phrase “-----BEGIN RSA PRIVATE KEY-----” and “-----END RSA PRIVATE KEY-----” and won’t accept a key that doesn’t have those phrases.

Anyone got LE to work on DreamHost? If so, how?

---

<div class="post-metadata">

**Author:** ![motoko](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/motoko/32/26328_2.png) [@motoko](https://community.letsencrypt.org/u/motoko)\
**Post date:** [December 4, 2015, 1:31am UTC](https://community.letsencrypt.org/t/error-adding-cert-invalid-private-key/5167/2 "2015-12-04T01:31:27Z")

</div>

Were there header and footer lines before? If so, what were they? How did you generate the key?

---

<div class="post-metadata">

**Author:** ![dafyk](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dafyk/32/2613_2.png) [@dafyk](https://community.letsencrypt.org/u/dafyk)\
**Post date:** [December 4, 2015, 11:28am UTC](https://community.letsencrypt.org/t/error-adding-cert-invalid-private-key/5167/3 "2015-12-04T11:28:30Z")

</div>

You need to convert your privkey.pem to RSA format. You can do that with openssl

`sudo openssl rsa -inform pem -in /etc/letsencrypt/live/www.example.com/privkey.pem -outform pem | less`

Command will print (not store) your RSA key which you can copy/paste to DH panel.

---

<div class="post-metadata">

**Author:** ![ksolomon](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ksolomon/32/2524_2.png) [@ksolomon](https://community.letsencrypt.org/u/ksolomon)\
**Post date:** [December 4, 2015, 4:00pm UTC](https://community.letsencrypt.org/t/error-adding-cert-invalid-private-key/5167/4 "2015-12-04T16:00:38Z")

</div>

Thanks!

That got it going. Now to set a reminder to renew it every 90 days!

---

<div class="post-metadata">

**Author:** ![hdfssk](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/hdfssk/32/2721_2.png) [@hdfssk](https://community.letsencrypt.org/u/hdfssk)\
**Post date:** [December 5, 2015, 12:06am UTC](https://community.letsencrypt.org/t/error-adding-cert-invalid-private-key/5167/5 "2015-12-05T00:06:36Z")

</div>

Another gotcha for DreamHost users: the panel’s ‘Manual configuration’ area shows boxes for _Certificate_, _Private Key_, and _Intermediate Certificate_… but just pasting the converted-to-RSA `privkey.pem` into _Private Key_ and `fullchain.pem` into _Certificate_ makes browsers give “sec\_error\_unknown\_issuer” type errors, because each box drops everything after the first `-----END CERTIFICATE-----` on save.

Pasting `cert.pem` into _Certificate_ and `chain.pem` into _Intermediate Certificate_ does work properly. Testing the newly secured domain at [https://whatsmychaincert.com](https://whatsmychaincert.com) is a helpful sanity check — if the test fails and tells you you should be using what’s in `chain.pem`, you’ll know something wasn’t pasted correctly or the changes haven’t pushed yet.

---

<div class="post-metadata">

**Author:** ![ksolomon](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ksolomon/32/2524_2.png) [@ksolomon](https://community.letsencrypt.org/u/ksolomon)\
**Post date:** [December 7, 2015, 4:06pm UTC](https://community.letsencrypt.org/t/error-adding-cert-invalid-private-key/5167/6 "2015-12-07T16:06:55Z")

</div>

Thanks.

I’ve generally avoided doing the full chain file when I’ve used certs in the past because of issues like this…but it’s helpful info for others who might not realize what’s going on and wonder why it’s not working.

---

<div class="post-metadata">

**Author:** ![volker48](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/volker48/32/4691_2.png) [@volker48](https://community.letsencrypt.org/u/volker48)\
**Post date:** [January 28, 2016, 6:46pm UTC](https://community.letsencrypt.org/t/error-adding-cert-invalid-private-key/5167/7 "2016-01-28T18:46:58Z")

</div>

Thanks this helped me on Media Temple as well. It kept giving me a key error, but they didn’t specify anywhere that they needed an RSA format pem file.
