Sample code for 30+ languages & platforms
Classic ASP

Convert a PuTTY Private Key (.ppk) to OpenSSH (.pem)

See more SSH Examples

Demonstrates converting a PuTTY format private key to OpenSSH format. The .ppk is imported with FromPuttyPrivateKey and re-exported with ToOpenSshPrivateKey, both unencrypted and encrypted.

Note: The file paths are relative to the application's current working directory. Supply the paths to your own files.

Background: PuTTY and OpenSSH store the same underlying key material in different container formats, so converting between them is a re-encoding rather than a new key — the corresponding public key, and therefore the server-side authorized_keys entry, is unchanged. This matters when moving between Windows tooling built around PuTTY and Unix tooling that expects PEM. Note that the Password property serves double duty: it decrypts the key on import and encrypts it on export, so set it appropriately for each step.

Chilkat Classic ASP Downloads

Classic ASP
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<%
success = 0

'  Demonstrates converting a PuTTY format private key (.ppk) to OpenSSH (.pem) format.

set key = Server.CreateObject("Chilkat.SshKey")

'  Set the password before importing an encrypted PuTTY key.  If the key is not encrypted it
'  makes no difference whether Password is set.  This should come from a secure source rather
'  than being hard-coded.
key.Password = "myKeyPassword"

'  LoadText is a convenience method that reads any text file into a string.  It does not itself
'  load the key.
keyStr = key.LoadText("qa_data/putty_private_key.ppk")
If (key.LastMethodSuccess = 0) Then
    Response.Write "<pre>" & Server.HTMLEncode( key.LastErrorText) & "</pre>"
    Response.End
End If

success = key.FromPuttyPrivateKey(keyStr)
If (success = 0) Then
    Response.Write "<pre>" & Server.HTMLEncode( key.LastErrorText) & "</pre>"
    Response.End
End If

'  Export to an unencrypted OpenSSH key.
bEncrypt = 0
unencryptedKeyStr = key.ToOpenSshPrivateKey(bEncrypt)
If (key.LastMethodSuccess = 0) Then
    Response.Write "<pre>" & Server.HTMLEncode( key.LastErrorText) & "</pre>"
    Response.End
End If

success = key.SaveText(unencryptedKeyStr,"qa_output/unencrypted_openssh.pem")
If (success = 0) Then
    Response.Write "<pre>" & Server.HTMLEncode( key.LastErrorText) & "</pre>"
    Response.End
End If

'  Export to an encrypted OpenSSH key.  The Password property supplies the passphrase used to
'  encrypt the output.
bEncrypt = 1
key.Password = "myExportPassword"
encryptedKeyStr = key.ToOpenSshPrivateKey(bEncrypt)
If (key.LastMethodSuccess = 0) Then
    Response.Write "<pre>" & Server.HTMLEncode( key.LastErrorText) & "</pre>"
    Response.End
End If

success = key.SaveText(encryptedKeyStr,"qa_output/encrypted_openssh.pem")
If (success = 0) Then
    Response.Write "<pre>" & Server.HTMLEncode( key.LastErrorText) & "</pre>"
    Response.End
End If

Response.Write "<pre>" & Server.HTMLEncode( "Done!") & "</pre>"

%>
</body>
</html>