no start line 🔒 SSL / TLS

OpenSSL: unable to load certificate / PEM routines:get_name:no start line (key values mismatch)

OpenSSL (or Nginx/Apache) couldn’t read the certificate or key — wrong file format, wrong file, or the key doesn’t match the certificate.

Seen on: OpenSSL

Meaning

PEM files must contain -----BEGIN CERTIFICATE----- / -----BEGIN PRIVATE KEY----- blocks. DER/PFX files, Windows line endings, BOMs, copied text with extra spaces, or swapping cert and key cause “no start line”. “key values mismatch” means the key belongs to another certificate.

Common causes

  • File is DER/PFX, not PEM
  • Cert and key paths swapped
  • Extra characters/BOM or missing BEGIN line
  • Private key from a different CSR (key values mismatch)

⚡ Quick fix

  1. Convert formats (openssl x509 -inform der / openssl pkcs12)
  2. Check the first line of each file
  3. Compare cert and key modulus/public key hashes

Detailed fix by platform

Shell

  1. bash
    head -1 cert.pem key.pem
    openssl x509 -inform der -in cert.cer -out cert.pem
    openssl x509 -noout -pubkey -in cert.pem | sha256sum; openssl pkey -pubout -in key.pem | sha256sum

How to diagnose

  1. Format — BEGIN line present?
  2. Match — Public key hashes equal?
  3. Paths — ssl_certificate vs ssl_certificate_key

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.