OpenSSL: unable to load certificate / PEM routines:get_name:no start line (key values mismatch)
OpenSSL (or Nginx/Apache) couldn’t read the certificate or key — wrong file format, wrong file, or the key doesn’t match the certificate.
Seen on:
OpenSSL
Meaning
PEM files must contain -----BEGIN CERTIFICATE----- / -----BEGIN PRIVATE KEY----- blocks. DER/PFX files, Windows line endings, BOMs, copied text with extra spaces, or swapping cert and key cause “no start line”. “key values mismatch” means the key belongs to another certificate.
Common causes
- File is DER/PFX, not PEM
- Cert and key paths swapped
- Extra characters/BOM or missing BEGIN line
- Private key from a different CSR (key values mismatch)
⚡ Quick fix
- Convert formats (openssl x509 -inform der / openssl pkcs12)
- Check the first line of each file
- Compare cert and key modulus/public key hashes
Detailed fix by platform
Shell
- bash
head -1 cert.pem key.pem openssl x509 -inform der -in cert.cer -out cert.pem openssl x509 -noout -pubkey -in cert.pem | sha256sum; openssl pkey -pubout -in key.pem | sha256sum
How to diagnose
- Format — BEGIN line present?
- Match — Public key hashes equal?
- Paths — ssl_certificate vs ssl_certificate_key
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- 526 Cloudflare Error 526: Invalid SSL Certificate
- Challenge failed for domain Let’s Encrypt / Certbot: Challenge failed for domain example.com — Invalid response from http://example.com/.well-known/acme-challenge/x: 404
- doesn't include signing certificate Provisioning profile "x" doesn't include signing certificate "Apple Development: Name (ID)"
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026