rsa.pod revision 1.1 1 1.1 christos =pod
2 1.1 christos
3 1.1 christos =head1 NAME
4 1.1 christos
5 1.1 christos openssl-rsa,
6 1.1 christos rsa - RSA key processing tool
7 1.1 christos
8 1.1 christos =head1 SYNOPSIS
9 1.1 christos
10 1.1 christos B<openssl> B<rsa>
11 1.1 christos [B<-help>]
12 1.1 christos [B<-inform PEM|DER>]
13 1.1 christos [B<-outform PEM|DER>]
14 1.1 christos [B<-in filename>]
15 1.1 christos [B<-passin arg>]
16 1.1 christos [B<-out filename>]
17 1.1 christos [B<-passout arg>]
18 1.1 christos [B<-aes128>]
19 1.1 christos [B<-aes192>]
20 1.1 christos [B<-aes256>]
21 1.1 christos [B<-aria128>]
22 1.1 christos [B<-aria192>]
23 1.1 christos [B<-aria256>]
24 1.1 christos [B<-camellia128>]
25 1.1 christos [B<-camellia192>]
26 1.1 christos [B<-camellia256>]
27 1.1 christos [B<-des>]
28 1.1 christos [B<-des3>]
29 1.1 christos [B<-idea>]
30 1.1 christos [B<-text>]
31 1.1 christos [B<-noout>]
32 1.1 christos [B<-modulus>]
33 1.1 christos [B<-check>]
34 1.1 christos [B<-pubin>]
35 1.1 christos [B<-pubout>]
36 1.1 christos [B<-RSAPublicKey_in>]
37 1.1 christos [B<-RSAPublicKey_out>]
38 1.1 christos [B<-engine id>]
39 1.1 christos
40 1.1 christos =head1 DESCRIPTION
41 1.1 christos
42 1.1 christos The B<rsa> command processes RSA keys. They can be converted between various
43 1.1 christos forms and their components printed out. B<Note> this command uses the
44 1.1 christos traditional SSLeay compatible format for private key encryption: newer
45 1.1 christos applications should use the more secure PKCS#8 format using the B<pkcs8>
46 1.1 christos utility.
47 1.1 christos
48 1.1 christos =head1 OPTIONS
49 1.1 christos
50 1.1 christos =over 4
51 1.1 christos
52 1.1 christos =item B<-help>
53 1.1 christos
54 1.1 christos Print out a usage message.
55 1.1 christos
56 1.1 christos =item B<-inform DER|PEM>
57 1.1 christos
58 1.1 christos This specifies the input format. The B<DER> option uses an ASN1 DER encoded
59 1.1 christos form compatible with the PKCS#1 RSAPrivateKey or SubjectPublicKeyInfo format.
60 1.1 christos The B<PEM> form is the default format: it consists of the B<DER> format base64
61 1.1 christos encoded with additional header and footer lines. On input PKCS#8 format private
62 1.1 christos keys are also accepted.
63 1.1 christos
64 1.1 christos =item B<-outform DER|PEM>
65 1.1 christos
66 1.1 christos This specifies the output format, the options have the same meaning and default
67 1.1 christos as the B<-inform> option.
68 1.1 christos
69 1.1 christos =item B<-in filename>
70 1.1 christos
71 1.1 christos This specifies the input filename to read a key from or standard input if this
72 1.1 christos option is not specified. If the key is encrypted a pass phrase will be
73 1.1 christos prompted for.
74 1.1 christos
75 1.1 christos =item B<-passin arg>
76 1.1 christos
77 1.1 christos The input file password source. For more information about the format of B<arg>
78 1.1 christos see L<openssl(1)/Pass Phrase Options>.
79 1.1 christos
80 1.1 christos =item B<-out filename>
81 1.1 christos
82 1.1 christos This specifies the output filename to write a key to or standard output if this
83 1.1 christos option is not specified. If any encryption options are set then a pass phrase
84 1.1 christos will be prompted for. The output filename should B<not> be the same as the input
85 1.1 christos filename.
86 1.1 christos
87 1.1 christos =item B<-passout password>
88 1.1 christos
89 1.1 christos The output file password source. For more information about the format of B<arg>
90 1.1 christos see L<openssl(1)/Pass Phrase Options>.
91 1.1 christos
92 1.1 christos =item B<-aes128>, B<-aes192>, B<-aes256>, B<-aria128>, B<-aria192>, B<-aria256>, B<-camellia128>, B<-camellia192>, B<-camellia256>, B<-des>, B<-des3>, B<-idea>
93 1.1 christos
94 1.1 christos These options encrypt the private key with the specified
95 1.1 christos cipher before outputting it. A pass phrase is prompted for.
96 1.1 christos If none of these options is specified the key is written in plain text. This
97 1.1 christos means that using the B<rsa> utility to read in an encrypted key with no
98 1.1 christos encryption option can be used to remove the pass phrase from a key, or by
99 1.1 christos setting the encryption options it can be use to add or change the pass phrase.
100 1.1 christos These options can only be used with PEM format output files.
101 1.1 christos
102 1.1 christos =item B<-text>
103 1.1 christos
104 1.1 christos Prints out the various public or private key components in
105 1.1 christos plain text in addition to the encoded version.
106 1.1 christos
107 1.1 christos =item B<-noout>
108 1.1 christos
109 1.1 christos This option prevents output of the encoded version of the key.
110 1.1 christos
111 1.1 christos =item B<-modulus>
112 1.1 christos
113 1.1 christos This option prints out the value of the modulus of the key.
114 1.1 christos
115 1.1 christos =item B<-check>
116 1.1 christos
117 1.1 christos This option checks the consistency of an RSA private key.
118 1.1 christos
119 1.1 christos =item B<-pubin>
120 1.1 christos
121 1.1 christos By default a private key is read from the input file: with this
122 1.1 christos option a public key is read instead.
123 1.1 christos
124 1.1 christos =item B<-pubout>
125 1.1 christos
126 1.1 christos By default a private key is output: with this option a public
127 1.1 christos key will be output instead. This option is automatically set if
128 1.1 christos the input is a public key.
129 1.1 christos
130 1.1 christos =item B<-RSAPublicKey_in>, B<-RSAPublicKey_out>
131 1.1 christos
132 1.1 christos Like B<-pubin> and B<-pubout> except B<RSAPublicKey> format is used instead.
133 1.1 christos
134 1.1 christos =item B<-engine id>
135 1.1 christos
136 1.1 christos Specifying an engine (by its unique B<id> string) will cause B<rsa>
137 1.1 christos to attempt to obtain a functional reference to the specified engine,
138 1.1 christos thus initialising it if needed. The engine will then be set as the default
139 1.1 christos for all available algorithms.
140 1.1 christos
141 1.1 christos =back
142 1.1 christos
143 1.1 christos =head1 NOTES
144 1.1 christos
145 1.1 christos The PEM private key format uses the header and footer lines:
146 1.1 christos
147 1.1 christos -----BEGIN RSA PRIVATE KEY-----
148 1.1 christos -----END RSA PRIVATE KEY-----
149 1.1 christos
150 1.1 christos The PEM public key format uses the header and footer lines:
151 1.1 christos
152 1.1 christos -----BEGIN PUBLIC KEY-----
153 1.1 christos -----END PUBLIC KEY-----
154 1.1 christos
155 1.1 christos The PEM B<RSAPublicKey> format uses the header and footer lines:
156 1.1 christos
157 1.1 christos -----BEGIN RSA PUBLIC KEY-----
158 1.1 christos -----END RSA PUBLIC KEY-----
159 1.1 christos
160 1.1 christos =head1 EXAMPLES
161 1.1 christos
162 1.1 christos To remove the pass phrase on an RSA private key:
163 1.1 christos
164 1.1 christos openssl rsa -in key.pem -out keyout.pem
165 1.1 christos
166 1.1 christos To encrypt a private key using triple DES:
167 1.1 christos
168 1.1 christos openssl rsa -in key.pem -des3 -out keyout.pem
169 1.1 christos
170 1.1 christos To convert a private key from PEM to DER format:
171 1.1 christos
172 1.1 christos openssl rsa -in key.pem -outform DER -out keyout.der
173 1.1 christos
174 1.1 christos To print out the components of a private key to standard output:
175 1.1 christos
176 1.1 christos openssl rsa -in key.pem -text -noout
177 1.1 christos
178 1.1 christos To just output the public part of a private key:
179 1.1 christos
180 1.1 christos openssl rsa -in key.pem -pubout -out pubkey.pem
181 1.1 christos
182 1.1 christos Output the public part of a private key in B<RSAPublicKey> format:
183 1.1 christos
184 1.1 christos openssl rsa -in key.pem -RSAPublicKey_out -out pubkey.pem
185 1.1 christos
186 1.1 christos =head1 BUGS
187 1.1 christos
188 1.1 christos There should be an option that automatically handles .key files,
189 1.1 christos without having to manually edit them.
190 1.1 christos
191 1.1 christos =head1 SEE ALSO
192 1.1 christos
193 1.1 christos L<pkcs8(1)>, L<dsa(1)>, L<genrsa(1)>,
194 1.1 christos L<gendsa(1)>
195 1.1 christos
196 1.1 christos =head1 COPYRIGHT
197 1.1 christos
198 1.1 christos Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.
199 1.1 christos
200 1.1 christos Licensed under the OpenSSL license (the "License"). You may not use
201 1.1 christos this file except in compliance with the License. You can obtain a copy
202 1.1 christos in the file LICENSE in the source distribution or at
203 1.1 christos L<https://www.openssl.org/source/license.html>.
204 1.1 christos
205 1.1 christos =cut
206