Home | History | Annotate | Line # | Download | only in man1
      1  1.1  christos =pod
      2  1.1  christos 
      3  1.1  christos =head1 NAME
      4  1.1  christos 
      5  1.1  christos openssl-dsa,
      6  1.1  christos dsa - DSA key processing
      7  1.1  christos 
      8  1.1  christos =head1 SYNOPSIS
      9  1.1  christos 
     10  1.1  christos B<openssl> B<dsa>
     11  1.1  christos [B<-help>]
     12  1.1  christos [B<-inform PEM|DER>]
     13  1.1  christos [B<-outform PEM|DER>]
     14  1.1  christos [B<-in filename>]
     15  1.1  christos [B<-passin arg>]
     16  1.1  christos [B<-out filename>]
     17  1.1  christos [B<-passout arg>]
     18  1.1  christos [B<-aes128>]
     19  1.1  christos [B<-aes192>]
     20  1.1  christos [B<-aes256>]
     21  1.1  christos [B<-aria128>]
     22  1.1  christos [B<-aria192>]
     23  1.1  christos [B<-aria256>]
     24  1.1  christos [B<-camellia128>]
     25  1.1  christos [B<-camellia192>]
     26  1.1  christos [B<-camellia256>]
     27  1.1  christos [B<-des>]
     28  1.1  christos [B<-des3>]
     29  1.1  christos [B<-idea>]
     30  1.1  christos [B<-text>]
     31  1.1  christos [B<-noout>]
     32  1.1  christos [B<-modulus>]
     33  1.1  christos [B<-pubin>]
     34  1.1  christos [B<-pubout>]
     35  1.1  christos [B<-engine id>]
     36  1.1  christos 
     37  1.1  christos =head1 DESCRIPTION
     38  1.1  christos 
     39  1.1  christos The B<dsa> command processes DSA keys. They can be converted between various
     40  1.1  christos forms and their components printed out. B<Note> This command uses the
     41  1.1  christos traditional SSLeay compatible format for private key encryption: newer
     42  1.1  christos applications should use the more secure PKCS#8 format using the B<pkcs8>
     43  1.1  christos 
     44  1.1  christos =head1 OPTIONS
     45  1.1  christos 
     46  1.1  christos =over 4
     47  1.1  christos 
     48  1.1  christos =item B<-help>
     49  1.1  christos 
     50  1.1  christos Print out a usage message.
     51  1.1  christos 
     52  1.1  christos =item B<-inform DER|PEM>
     53  1.1  christos 
     54  1.1  christos This specifies the input format. The B<DER> option with a private key uses
     55  1.1  christos an ASN1 DER encoded form of an ASN.1 SEQUENCE consisting of the values of
     56  1.1  christos version (currently zero), p, q, g, the public and private key components
     57  1.1  christos respectively as ASN.1 INTEGERs. When used with a public key it uses a
     58  1.1  christos SubjectPublicKeyInfo structure: it is an error if the key is not DSA.
     59  1.1  christos 
     60  1.1  christos The B<PEM> form is the default format: it consists of the B<DER> format base64
     61  1.1  christos encoded with additional header and footer lines. In the case of a private key
     62  1.1  christos PKCS#8 format is also accepted.
     63  1.1  christos 
     64  1.1  christos =item B<-outform DER|PEM>
     65  1.1  christos 
     66  1.1  christos This specifies the output format, the options have the same meaning and default
     67  1.1  christos as the B<-inform> option.
     68  1.1  christos 
     69  1.1  christos =item B<-in filename>
     70  1.1  christos 
     71  1.1  christos This specifies the input filename to read a key from or standard input if this
     72  1.1  christos option is not specified. If the key is encrypted a pass phrase will be
     73  1.1  christos prompted for.
     74  1.1  christos 
     75  1.1  christos =item B<-passin arg>
     76  1.1  christos 
     77  1.1  christos The input file password source. For more information about the format of B<arg>
     78  1.1  christos see L<openssl(1)/Pass Phrase Options>.
     79  1.1  christos 
     80  1.1  christos =item B<-out filename>
     81  1.1  christos 
     82  1.1  christos This specifies the output filename to write a key to or standard output by
     83  1.1  christos is not specified. If any encryption options are set then a pass phrase will be
     84  1.1  christos prompted for. The output filename should B<not> be the same as the input
     85  1.1  christos filename.
     86  1.1  christos 
     87  1.1  christos =item B<-passout arg>
     88  1.1  christos 
     89  1.1  christos The output file password source. For more information about the format of B<arg>
     90  1.1  christos see L<openssl(1)/Pass Phrase Options>.
     91  1.1  christos 
     92  1.1  christos =item B<-aes128>, B<-aes192>, B<-aes256>, B<-aria128>, B<-aria192>, B<-aria256>, B<-camellia128>, B<-camellia192>, B<-camellia256>, B<-des>, B<-des3>, B<-idea>
     93  1.1  christos 
     94  1.1  christos These options encrypt the private key with the specified
     95  1.1  christos cipher before outputting it. A pass phrase is prompted for.
     96  1.1  christos If none of these options is specified the key is written in plain text. This
     97  1.1  christos means that using the B<dsa> utility to read in an encrypted key with no
     98  1.1  christos encryption option can be used to remove the pass phrase from a key, or by
     99  1.1  christos setting the encryption options it can be use to add or change the pass phrase.
    100  1.1  christos These options can only be used with PEM format output files.
    101  1.1  christos 
    102  1.1  christos =item B<-text>
    103  1.1  christos 
    104  1.1  christos Prints out the public, private key components and parameters.
    105  1.1  christos 
    106  1.1  christos =item B<-noout>
    107  1.1  christos 
    108  1.1  christos This option prevents output of the encoded version of the key.
    109  1.1  christos 
    110  1.1  christos =item B<-modulus>
    111  1.1  christos 
    112  1.1  christos This option prints out the value of the public key component of the key.
    113  1.1  christos 
    114  1.1  christos =item B<-pubin>
    115  1.1  christos 
    116  1.1  christos By default, a private key is read from the input file. With this option a
    117  1.1  christos public key is read instead.
    118  1.1  christos 
    119  1.1  christos =item B<-pubout>
    120  1.1  christos 
    121  1.1  christos By default, a private key is output. With this option a public
    122  1.1  christos key will be output instead. This option is automatically set if the input is
    123  1.1  christos a public key.
    124  1.1  christos 
    125  1.1  christos =item B<-engine id>
    126  1.1  christos 
    127  1.1  christos Specifying an engine (by its unique B<id> string) will cause B<dsa>
    128  1.1  christos to attempt to obtain a functional reference to the specified engine,
    129  1.1  christos thus initialising it if needed. The engine will then be set as the default
    130  1.1  christos for all available algorithms.
    131  1.1  christos 
    132  1.1  christos =back
    133  1.1  christos 
    134  1.1  christos =head1 NOTES
    135  1.1  christos 
    136  1.1  christos The PEM private key format uses the header and footer lines:
    137  1.1  christos 
    138  1.1  christos  -----BEGIN DSA PRIVATE KEY-----
    139  1.1  christos  -----END DSA PRIVATE KEY-----
    140  1.1  christos 
    141  1.1  christos The PEM public key format uses the header and footer lines:
    142  1.1  christos 
    143  1.1  christos  -----BEGIN PUBLIC KEY-----
    144  1.1  christos  -----END PUBLIC KEY-----
    145  1.1  christos 
    146  1.1  christos =head1 EXAMPLES
    147  1.1  christos 
    148  1.1  christos To remove the pass phrase on a DSA private key:
    149  1.1  christos 
    150  1.1  christos  openssl dsa -in key.pem -out keyout.pem
    151  1.1  christos 
    152  1.1  christos To encrypt a private key using triple DES:
    153  1.1  christos 
    154  1.1  christos  openssl dsa -in key.pem -des3 -out keyout.pem
    155  1.1  christos 
    156  1.1  christos To convert a private key from PEM to DER format:
    157  1.1  christos 
    158  1.1  christos  openssl dsa -in key.pem -outform DER -out keyout.der
    159  1.1  christos 
    160  1.1  christos To print out the components of a private key to standard output:
    161  1.1  christos 
    162  1.1  christos  openssl dsa -in key.pem -text -noout
    163  1.1  christos 
    164  1.1  christos To just output the public part of a private key:
    165  1.1  christos 
    166  1.1  christos  openssl dsa -in key.pem -pubout -out pubkey.pem
    167  1.1  christos 
    168  1.1  christos =head1 SEE ALSO
    169  1.1  christos 
    170  1.1  christos L<dsaparam(1)>, L<gendsa(1)>, L<rsa(1)>,
    171  1.1  christos L<genrsa(1)>
    172  1.1  christos 
    173  1.1  christos =head1 COPYRIGHT
    174  1.1  christos 
    175  1.1  christos Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.
    176  1.1  christos 
    177  1.1  christos Licensed under the OpenSSL license (the "License").  You may not use
    178  1.1  christos this file except in compliance with the License.  You can obtain a copy
    179  1.1  christos in the file LICENSE in the source distribution or at
    180  1.1  christos L<https://www.openssl.org/source/license.html>.
    181  1.1  christos 
    182  1.1  christos =cut
    183