Help
Digital certificate on Mac: install it and find it
Guide updated: · by nexoapex
To install a backup of your FNMT digital certificate on a Mac, import the .p12 or .pfx file into Keychain Access so Safari and Chrome can use it. If you have an electronic ID card, follow the DNIe guide: its private key stays on the card. These are two different ways to identify yourself and sign.
Do you have a file or a card?
Before installing anything, identify what you have. This determines which instructions you need:
| What you have | Next step |
|---|---|
| Personal .p12 or .pfx backup | Import it on your Mac using the backup password. |
| Only a .cer or .crt file | It does not contain the private key you need to identify yourself. You need your personal backup with its private key; changing the extension will not add it. |
| Physical DNIe card | You need a reader, your PIN and software that reads the card. Set up your DNIe on Mac. |
| You do not have a certificate yet | See the official FNMT options or apply using your DNIe. |
Spain’s Tax Agency (AEAT) explains why a backup without the private key cannot be used to log in. A certificate authority’s public certificate is not your personal certificate either.
How to install a digital certificate for Safari and Chrome
- Search for Keychain Access in Spotlight and open the app.
- Select the login keychain. Choose File > Import Items and open your .p12 or .pfx file.
- Enter the password used to protect that backup. It is not necessarily your Mac password or DNIe PIN.
- Find your identity under My Certificates. Check the holder, issuer and expiry date before selecting it on a government website.
The AEAT documents this import for Safari and Chrome: both use the Mac’s keychain. To open the utility in recent versions, Apple says to search for it in Spotlight.
Where is my digital certificate on a Mac?
For Safari and Chrome, look in Keychain Access, login, My Certificates. If you imported it into Firefox, also check its own certificate store: Settings > Privacy & Security > Certificates > View Certificates > Your Certificates.
To import it directly into Firefox, click Import in that tab and select the .p12 or .pfx backup. The AEAT guide for Firefox explains the backup password. Do not confuse this step with loading the DNIe PKCS#11 module.
It is installed but does not work: what to check
- It does not appear when you open a government website: check that you imported an identity with its private key into the store your browser uses. A .cer file alone is not enough.
- It has expired: importing the same backup again does not renew its validity. Check its status with the issuer. The AEAT explains how to find expired certificates.
- You can log in, but signing fails: identification and signing are separate steps. If the website opens AutoFirma, see AutoFirma errors on Mac.
- It is your DNIe certificate: follow the checks for DNIe in Safari and Chrome and DNIe PIN and certificates. Do not try to convert it into a .p12 file.
Can I obtain an FNMT certificate using my DNIe on Mac?
The FNMT lets you apply for a certificate using a valid, unrevoked DNIe, without visiting an office to prove your identity. A separate certificate is issued: the card’s private key is not exported.
- Prepare your reader and DNIe. Follow the FNMT’s preliminary setup, which includes the FNMT-RCM Configurator, AutoFirma and DNIe software. Its section for M chips says to open the Configurator and accept Rosetta if prompted.
- Complete the application using your DNIe and keep the new password: the FNMT warns that if you forget it, you will have to start a new application.
- Download it using the same computer, browser and user account used for the application. Keep a protected backup.
These instructions are based on official documentation consulted on 29 September 2026; they do not represent a test of this procedure with DNIe Pro. The Configurator generates the application’s keys, and AutoFirma handles signing when the procedure requires it.
How do I make a backup for another computer?
In Keychain Access, select your personal certificate and choose File > Export Items. Choose .p12 and protect the backup with a password. The AEAT documents how to make a backup on a Mac. If .p12 is unavailable, check that you have the private key; exporting only the public certificate does not create a backup you can use for signing.
When do you need DNIe for Mac?
To use your DNIe card. The app lets you read it and sign documents with it; DNIe Pro adds browser integration. It does not import or manage FNMT software certificates in .p12/.pfx files. If you already have one, follow the instructions above; to sign with it, see AutoFirma. To use your card, start by setting up your DNIe on Mac.