Sample code for 30+ languages & platforms
Rust

Convert a PuTTY Private Key (.ppk) to OpenSSH (.pem)

See more SSH Examples

Demonstrates converting a PuTTY format private key to OpenSSH format. The .ppk is imported with FromPuttyPrivateKey and re-exported with ToOpenSshPrivateKey, both unencrypted and encrypted.

Note: The file paths are relative to the application's current working directory. Supply the paths to your own files.

Background: PuTTY and OpenSSH store the same underlying key material in different container formats, so converting between them is a re-encoding rather than a new key — the corresponding public key, and therefore the server-side authorized_keys entry, is unchanged. This matters when moving between Windows tooling built around PuTTY and Unix tooling that expects PEM. Note that the Password property serves double duty: it decrypts the key on import and encrypts it on export, so set it appropriately for each step.

Chilkat Rust Downloads

Rust

// Demonstrates converting a PuTTY format private key (.ppk) to OpenSSH (.pem) format.

let key = chilkat::SshKey::new();

// Set the password before importing an encrypted PuTTY key.  If the key is not encrypted it
// makes no difference whether Password is set.  This should come from a secure source rather
// than being hard-coded.
key.set_password("myKeyPassword");

// LoadText is a convenience method that reads any text file into a string.  It does not itself
// load the key.
let Ok(key_str) = key.load_text("qa_data/putty_private_key.ppk") else {
    println!("{}", key.last_error_text());
    return;
};

if key.from_putty_private_key(&key_str).is_err() {
    println!("{}", key.last_error_text());
    return;
}

// Export to an unencrypted OpenSSH key.
let mut b_encrypt = false;
let Ok(unencrypted_key_str) = key.to_open_ssh_private_key(b_encrypt) else {
    println!("{}", key.last_error_text());
    return;
};

if key.save_text(&unencrypted_key_str, "qa_output/unencrypted_openssh.pem").is_err() {
    println!("{}", key.last_error_text());
    return;
}

// Export to an encrypted OpenSSH key.  The Password property supplies the passphrase used to
// encrypt the output.
b_encrypt = true;
key.set_password("myExportPassword");
let Ok(encrypted_key_str) = key.to_open_ssh_private_key(b_encrypt) else {
    println!("{}", key.last_error_text());
    return;
};

if key.save_text(&encrypted_key_str, "qa_output/encrypted_openssh.pem").is_err() {
    println!("{}", key.last_error_text());
    return;
}

println!("Done!");