.P7B

P7B File

PKCS
Ask a question
QUICK ANSWER

A P7B file is a PKCS #7 certificate bundle containing one or more X.509 CA certificates (typically a root and intermediates) but no private key. On Windows, double-click to open the Certificate Import Wizard. On Linux or macOS, use OpenSSL to inspect or convert it. The file is safe to share because it carries no private key material.

Developer: RSA Security (PKCS #7 spec, 1993); standardised as RFC 2315 / RFC 5652 (CMS) by IETF Category: Web Files Open standard MIME: application/x-pkcs7-certificates
OPENS ON Windows macOS Linux

On this page

19k+ extensions indexed
Last reviewed Jun 29, 2026

Not sure what your file is?

Drop any file into our identifier - we read just the first bytes to name the format.

Identify a file

What is the P7B file format?

A .p7b file is a PKCS #7 certificate chain container used in PKI (Public Key Infrastructure). It holds one or more X.509 digital certificates - typically a server certificate plus intermediate and root CA certificates - encoded in either binary DER or Base64 PEM format. Unlike .P12 bundles, a .p7b file contains no private key and is safe to distribute freely.

The format was defined by RSA Security in 1993 as PKCS #7 v1.5, later standardized by the IETF as RFC 2315 (1998), and superseded in specification by the Cryptographic Message Syntax (CMS) defined in RFC 5652 (2009). Despite the updated standard, .p7b remains the practical default for exporting and importing certificate chains on Windows systems.

Common uses:

  • Exporting certificate chains from Windows Certificate Manager (certmgr.msc)
  • Installing intermediate CA certificates on IIS and other Windows-based servers
  • Distributing trusted root CA bundles

The .p7c extension is functionally identical to .p7b. Tools such as OpenSSL can convert .p7b files to .PEM or .CER format as needed by Apache, nginx, and other servers that require a separate chain file alongside the private key.

Security & safety

RISK: LOW

P7B files contain only public certificate data - no private key, no executable code. They are safe to open and share. Verify the issuer chain matches a trusted CA before importing into a certificate store, to avoid trusting a rogue CA.

Format details

in a nutshell
FULL NAMEPKCSaka PKCS7 certificate file, CMS certificate chain
DEVELOPERRSA Security (PKCS #7 spec, 1993); standardised as RFC 2315 / RFC 5652 (CMS) by IETFsince 1993 (PKCS #7 v1.5 by RSA Security); RFC 2315 published 1998
CATEGORYWeb Files
MIME TYPEapplication/x-pkcs7-certificates
TYPECertificate chain container (DER binary or PEM Base64-encoded)
STANDARDOpen · royalty-free
This extension is also used by…
  • S/MIME Signed Message (.p7m) - PKCS #7 is also used for email signing (.p7m) and detached signatures (.p7s); those extensions are distinct.
MAGIC BYTES · FILE SIGNATURE
OFFSET
0001
HEX
3082
ASCII
0·
DER-encoded: starts with 0x30 (ASN.1 SEQUENCE tag) followed by 0x82 (length in 2 bytes). PEM-encoded: starts with the ASCII string "-----BEGIN PKCS7-----", Base64 content, then "-----END PKCS7-----". ~20% of P7B files are PEM; the rest are binary DER.

Programs that open P7B files

Windows2 apps
Windows Certificate Manager (certmgr.msc) Built-in Double-click the .p7b file → Certificate Import Wizard; or run 'certutil -addstore Root file.p7b'.
OpenSSL (Windows port) Open-source openssl pkcs7 -print_certs -in chain.p7b -out chain.pem (convert to PEM for review)
macOS2 apps
OpenSSL Open-source openssl pkcs7 -print_certs -in chain.p7b -out chain.pem
Keychain Access Built-in Double-click the .p7b file to import certificates into Keychain.
Linux1 app
OpenSSL Open-source openssl pkcs7 -print_certs -inform DER -in chain.p7b -out chain.pem (or -inform PEM for PEM input)

Technical details

deep spec
EncodingBinary DER or text Base64 (PEM)
Byte orderBig-endian (ASN.1 DER)
Container formatASN.1 DER or PEM wrapper
MIME typeapplication/x-pkcs7-certificates
Magic bytes (DER)0x30 0x82 - ASN.1 SEQUENCE tag with 2-byte length
Magic bytes (PEM)ASCII "-----BEGIN PKCS7-----" header line
Private key includedNo - certificates only; public data safe to share
Typical file size1 KB - 20 KB
Internal structureASN.1 ContentInfo with contentType=signedData; certificates field is a SET of X.509 v3 DER structures
Optional contentMay include Certificate Revocation Lists (CRLs)
Equivalent extension.p7c - functionally identical SignedData structure
Governing standardPKCS #7 v1.5 (RFC 2315, 1998); superseded by CMS RFC 5652 (2009)
Released1993 (PKCS #7 v1.5 by RSA Security); RFC 2315 published 1998
Latest versionRFC 5652 - Cryptographic Message Syntax (CMS), 2009
Open standardYes · royalty-free
Specificationdatatracker.ietf.org

P7B conversions

Community Q&A

asked by users
Ask a quick question
Get help from people who work with P7B files. Be specific - include your system and software version.
No account needed · answers usually within a day

No questions yet - be the first to ask about P7B files.

Frequently asked questions

What is a P7B file?
A PKCS #7 certificate bundle - contains one or more X.509 CA certificates (a trust chain) but NO private key. Used to install intermediate/root CA certs on web servers and Windows machines.
How do I open a P7B file on Windows?
Double-click to launch the Certificate Import Wizard, or open certmgr.msc, right-click a certificate store → All Tasks → Import.
How do I convert P7B to PEM for Apache or nginx?
Use OpenSSL: 'openssl pkcs7 -print_certs -inform DER -in chain.p7b -out chain.pem'. The output PEM can be used directly in SSLCertificateChainFile / ssl_trusted_certificate directives.
Does a P7B file contain a private key?
No. P7B (PKCS #7 SignedData) holds only public certificates. To bundle certificates WITH a private key, use PFX/P12 format.
What is the difference between P7B and PFX?
P7B contains public certs only (safe to share). PFX/P12 contains certs AND the private key (must be protected with a password).
What's the difference between P7B and CER?
A .cer file usually holds a single certificate; a .p7b can bundle an entire chain (root + intermediates) in one file.

References

1RFC 5652 - Cryptographic Message Syntax (CMS)datatracker.ietf.org
2RFC 2315 - PKCS #7 v1.5 (historic)datatracker.ietf.org

Keep exploring

across the database

Top extensions this week

1.AQQAQQ Instant Messenger File
2.CRDOWNLOADChrome Partial Download File
3.PARTPartial Download File
4.DATProgram Data File (generic)
5.EXEWindows Executable (Portable Executable)
6.BINCD/DVD Disc Image (BIN/CUE)
7.RPMSGRestricted Permission Message
8.TMPTemporary File
9.NOMEDIAAndroid No-Media Marker File
10.MDMarkdown Document

Related extensions

.CRDOWNLOADChrome Partial Download File
.JNLPJava Network Launch Protocol file
.WEBARCHIVESafari Web Archive
.PARTPartial Download File
.DOWNLOADPartial / Incomplete Download File
.ASPXActive Server Page Extended (ASP.NET Web Form)

Free file tools

An in-browser file identifier and image converter - everything runs on your device.

Open the toolbox

Browse file extensions A-Z