Generate OpenSSL RSA Key Pair from the Command Line
While Encrypting a File with a Password from the Command Line using OpenSSL is very useful in its own right, the real power of the OpenSSL library is its ability to support public key cryptography: encrypting or validating data in an unattended manner, where the password protecting the private key is never needed by the process doing the encrypting or validating.
A note on this update: this post has been part of the blog since 2012, and the
underlying RSA commands still work exactly as they did then. What has changed is
OpenSSL itself. Modern OpenSSL writes private keys in PKCS#8 format by default
(-----BEGIN PRIVATE KEY----- or -----BEGIN ENCRYPTED PRIVATE KEY-----) instead
of the older PKCS#1 format (-----BEGIN RSA PRIVATE KEY-----) this post originally
showed, and 3DES, the cipher originally used below to encrypt the private key, is
now deprecated by NIST for new applications.
I updated the commands and example output below to match, swapping in AES-256.
Nothing about how RSA itself works has changed, only the on-disk format and cipher
choice needed a refresh.
The Commands to Run
Generate a 2048 bit RSA Key
You can generate a public and private RSA key pair like this:
openssl genrsa -aes256 -out private.pem 2048That generates a 2048-bit RSA key pair and writes it, encrypted with AES-256
using a password you provide, to private.pem. You need to next extract the
public key file. You will use this, for instance, on your web server to
encrypt content so that it can only be read with the private key.
Export the RSA Public Key to a File
This command extracts the public key from your private key file and writes it to its own file:
openssl rsa -in private.pem -outform PEM -pubout -out public.pemThe -pubout flag is really important. Be sure to include it.
Next open the public.pem and ensure that it starts with
-----BEGIN PUBLIC KEY-----. This is how you know that this file is the
public key of the pair and not a private key.
To check the file from the command line you can use the less command, like this:
less public.pem
Do Not Run This, it Exports the Private Key
A previous version of the post gave this example in error.
openssl rsa -in private.pem -out private_unencrypted.pem -outform PEMThe error is that the -pubout was dropped from the end of the command.
That changes the meaning of the command from that of exporting the public key
to exporting the private key outside of its encrypted wrapper. Inspecting the
output file, in this case private_unencrypted.pem, clearly shows that the key
is unencrypted, since it now starts with -----BEGIN PRIVATE KEY----- instead
of -----BEGIN ENCRYPTED PRIVATE KEY-----.
Visually Inspect Your Key Files
It is important to visually inspect your private and public key files to make
sure that they are what you expect. With the AES-256 encryption used above,
OpenSSL will label the private key block -----BEGIN ENCRYPTED PRIVATE KEY-----
and the public key block -----BEGIN PUBLIC KEY-----. Unlike the older
PKCS#1 format, this header doesn’t name the algorithm (RSA, EC, etc.) directly;
that detail is encoded inside the file itself. So treat the header as
confirmation you have an encrypted private key, not proof that it’s
specifically an RSA key.
You can use less to inspect each of your two files in turn:
less private.pemto verify that it starts with-----BEGIN ENCRYPTED PRIVATE KEY-----less public.pemto verify that it starts with-----BEGIN PUBLIC KEY-----
The next section shows a full example of what each key file should look like.
The Generated Key Files
The generated files are base64-encoded encryption keys in plain text format. If you select a password for your private key, its file will be encrypted with your password. Be sure to remember this password or the key pair becomes useless.
The private.pem file looks something like this:
-----BEGIN ENCRYPTED PRIVATE KEY-----
MIIFNTBfBgkqhkiG9w0BBQ0wUjAxBgkqhkiG9w0BBQwwJAQQrt33TkHfK7KFGQX8
+Iu5IwICCAAwDAYIKoZIhvcNAgkFADAdBglghkgBZQMEASoEEI8l8eSzNhh2UlnF
7LIBt/0EggTQbjqcV5p4TDdDTy66rWkqofDiB63t2QOrfZbfcwfi/0jIyXZIsewI
1Up9JTQB1eGybRouAEA5TAOEP26+yw1jXgBH0VG2RqChGFnnCmXGU26CptQRZHSB
m9OYNJaAhHTvCPgReH+lKZ4KQpzpT4Vq7KEcDooTYx3VgrOXJdPrKNZj4EwhYW7E
rOBVh3oGdLnxmYqSs4AfDjCWdnL8ZPMY3dG7LtwMBglK9DL5Ow5KK2gxDlXnQlik
z2UgR2LPQcXCf0SCrQm8Xn3+UeQWEBiis3T9LMJuF+vozIOxxcPnBT7KOwM3+XCu
hS5WSMmm8fFx4x2NbAqWx1H/XnoOQGWN1Ed1Yy5rNXzKO6JvF5t3Ajw47XvKcq83
33+JHne33pL4cML6WBf2Pr9t+7oG5roh9nM4r0Zvd25Ng+2K3gIpl3nHEzauM83A
JSnEc+wfnfQ1fUjwwc8Dy6k1MfsRTLSwUaHEQ3DObPeu22yz+nozwr28sQ2FvnSj
hcMzcGzV8Xj4AQUklBJ81EadktAzKBuuU+oWhLH5ywgGQS1xtnD17G2KGcvqYL5l
3ckNfGHIdBccPxk1xZOQ1jyVEL7iZ5gVB51goGUVy0B8tA0W1yh7tNeHSh1qdn+d
Amo0n+47d5S/VFFez7bsWz/hIuOz5yi+mXOWjxNGxlrinx95Scr/SSIE2y9BwLIP
Sj6CtDKOFUU+c+8fqh86tUp7VybGNfaf3iim2I26No5LrubQSSVEjMlu7mzD4m3l
V2xe7jVE+rGfuL6HT2Y40fWkND0humwSMlrfDfABP6Gs8NK+BoAKAHiMTzyfBqOD
lwWfWT7cPWFggo3WzJUPD8pv+4GxNql0K6CtZGSFgE0cnf2b8YJw282qL65LZsKg
n/x7BmN+XDaF8hvcOiYNGGM7bUPYSyHrlofn0TZQ7Me4ynx1Q7wZapI/V1va+E2D
QhPWYt0PFJTRpVbJ60fJE4md5M11gtk47fNR1rF41/+SAerG7FBkjodvxqhLnwpn
bRAjN+rsUdly0SOyLbkRgaPXsPMLqHeKnaae8r/2wlNWGxcyi8yMN0lAbkgol+oB
dUDPJlLrSHLKZZEmPQpWlw+85fm9SJ5G05zVcBiDDGrDblqToSlcOTfkZ0Awbm5A
/c522pz3xGyME4gxne6EVW5lD93xauIDtOgCONuj7VfIeva5ZkH6HRHreafMxTIi
pHJKePY/SfGutxz2r4eTDVBFt5XdqnPBf96m/hBwIBpDnPlrmRS2dpKqBEU8/oOs
k1ibzkwP397FQemoSinukwra/FkFu/ZKudeXCbrXZoCqCcuUu3TeXwAURI+b50fr
HcBJZ9pYo8dcicRAKgf+XVSIhgaIq0HhC9CMKlspnozFeQicDNQqyOlwwKGncsUy
6jchAUqKKwiJsNbf3BCnODjketV9owiCtRNq3c8aWBJ32MtsN45HG4wF5gb19vRI
K0LPTZz4vL2xiTIccB8dugK9dJF253yiWuThEjDuyQ/QNEg4TomoWH/H/LkY4iCW
me3XVE4dGuXCr/7b182ufWetdX8FdsZY26rBsLSpVTVODsPVXgewLtkR1VqiPC/X
G1+5SW+k+qVOM1o2o0rZZjTGSoVfKjNiUwvLXZruAryDw0E3mLSZPA4=
-----END ENCRYPTED PRIVATE KEY-----The public key, public.pem, file looks like:
-----BEGIN PUBLIC KEY-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwpPJHVrvy9tmzkQSd08k
FulbPgjV6IvUmreah0d50rBuK1OKsCU7RITU89/xRiEGsU0rqne559w7917la00t
qT5RJV4L5AEqVJM0ozv9mdquHNnxs5p7eVzsZqZ6GuRS0KA973Ai4f+k+hA0aPM8
xLaDX9WQ0TNmXuYMGfO8XM/+eUwoEwyvnIEUUv0JpAHoU9DBLnsDHtDPI9KiORIQ
+lEDg/tmkW3S6QOEsHjjeAXpzuKlrub88NqsgaYhvy/KYpsE4mBisznubxIyhKXL
LlWZEJqVFouWJIsqIvJfzc8I9mMFVubZ1jPnCa/S/STwyIXp5cjoX0780LOl/4uU
mwIDAQAB
-----END PUBLIC KEY-----Protecting Your Keys
Depending on the nature of the information you will protect, it’s important to keep the private key backed up and secret. The public key can be distributed anywhere or embedded in your web application scripts, such as in your PHP, Ruby, or other scripts. Again, backup your keys!
Remember, if the key goes away the data encrypted to it is gone. Keeping a printed copy of the key material in a sealed envelope in a bank safety deposit box is a good way to protect important keys against loss due to fire or hard drive failure.
Now that you have a key pair, the natural next step is putting it to work. See Encrypt Data with an RSA Key with PHP for how to actually use it to protect data in an application, and browse the Encryption tag for the rest of the OpenSSL series.
Oh, and one last thing.
If you, dear reader, were planning any funny business with the private key that I have just published here. Know that they were made especially for this series of blog posts. I do not use them for anything else.