Sample code for 30+ languages & platforms
Delphi DLL

Convert a PuTTY Private Key (.ppk) to OpenSSH (.pem)

See more SSH Examples

Demonstrates converting a PuTTY format private key to OpenSSH format. The .ppk is imported with FromPuttyPrivateKey and re-exported with ToOpenSshPrivateKey, both unencrypted and encrypted.

Note: The file paths are relative to the application's current working directory. Supply the paths to your own files.

Background: PuTTY and OpenSSH store the same underlying key material in different container formats, so converting between them is a re-encoding rather than a new key — the corresponding public key, and therefore the server-side authorized_keys entry, is unchanged. This matters when moving between Windows tooling built around PuTTY and Unix tooling that expects PEM. Note that the Password property serves double duty: it decrypts the key on import and encrypts it on export, so set it appropriately for each step.

Chilkat Delphi DLL Downloads

Delphi DLL
var
success: Boolean;
key: HCkSshKey;
keyStr: PWideChar;
bEncrypt: Boolean;
unencryptedKeyStr: PWideChar;
encryptedKeyStr: PWideChar;

begin
success := False;

//  Demonstrates converting a PuTTY format private key (.ppk) to OpenSSH (.pem) format.

key := CkSshKey_Create();

//  Set the password before importing an encrypted PuTTY key.  If the key is not encrypted it
//  makes no difference whether Password is set.  This should come from a secure source rather
//  than being hard-coded.
CkSshKey_putPassword(key,'myKeyPassword');

//  LoadText is a convenience method that reads any text file into a string.  It does not itself
//  load the key.
keyStr := CkSshKey__loadText(key,'qa_data/putty_private_key.ppk');
if (CkSshKey_getLastMethodSuccess(key) = False) then
  begin
    Memo1.Lines.Add(CkSshKey__lastErrorText(key));
    Exit;
  end;

success := CkSshKey_FromPuttyPrivateKey(key,keyStr);
if (success = False) then
  begin
    Memo1.Lines.Add(CkSshKey__lastErrorText(key));
    Exit;
  end;

//  Export to an unencrypted OpenSSH key.
bEncrypt := False;
unencryptedKeyStr := CkSshKey__toOpenSshPrivateKey(key,bEncrypt);
if (CkSshKey_getLastMethodSuccess(key) = False) then
  begin
    Memo1.Lines.Add(CkSshKey__lastErrorText(key));
    Exit;
  end;

success := CkSshKey_SaveText(key,unencryptedKeyStr,'qa_output/unencrypted_openssh.pem');
if (success = False) then
  begin
    Memo1.Lines.Add(CkSshKey__lastErrorText(key));
    Exit;
  end;

//  Export to an encrypted OpenSSH key.  The Password property supplies the passphrase used to
//  encrypt the output.
bEncrypt := True;
CkSshKey_putPassword(key,'myExportPassword');
encryptedKeyStr := CkSshKey__toOpenSshPrivateKey(key,bEncrypt);
if (CkSshKey_getLastMethodSuccess(key) = False) then
  begin
    Memo1.Lines.Add(CkSshKey__lastErrorText(key));
    Exit;
  end;

success := CkSshKey_SaveText(key,encryptedKeyStr,'qa_output/encrypted_openssh.pem');
if (success = False) then
  begin
    Memo1.Lines.Add(CkSshKey__lastErrorText(key));
    Exit;
  end;

Memo1.Lines.Add('Done!');

CkSshKey_Dispose(key);