Home / Alt manpages / openssl-dsa(1ssl)

  • openssl-dsa(1ssl)
  • OpenSSL command
  • linux

Convert and inspect DSA keys safely with openssl dsa

You will use openssl dsa to inspect a DSA private key, export its public half, convert a private key between PEM and DER, and understand when the command writes an unencrypted or encrypted result. The examples keep the source file intact and show checks you can run after each operation.

Allow about fifteen minutes. You need a shell, OpenSSL and a readable DSA key. The local manpage is from the Ubuntu openssl package version 3.0.13-0ubuntu3.15. The executable found on this machine reports OpenSSL 3.6.1, so check your own version before relying on provider or compatibility details. No step needs elevated privileges unless the key is stored somewhere your account cannot read or write.

1. Check the installed command

Start with read-only version and help checks:

$ openssl version
OpenSSL 3.6.1 27 Jan 2026 (Library: OpenSSL 3.6.1 27 Jan 2026)
$ openssl dsa -help
Usage: dsa [options]

Your version may differ. The command is invoked as openssl dsa, even though its manual page is named openssl-dsa. The installed manual describes the DSA-specific processor as a legacy command. OpenSSL's pkey command can perform the same operations for DSA and supports other public-key types, so use dsa when you specifically need this interface or are maintaining an existing script.

Checkpoint

Continue only when openssl dsa -help prints usage text and returns successfully.

2. Inspect a private key without reprinting it

Use -text to print the DSA parameters and key components. Add -noout so the encoded private key is not printed a second time:

$ openssl dsa -in private.pem -text -noout
read DSA key
Private-Key: (1024 bit)
priv:
    ...
pub:
    ...
p:
    ...
q:
    ...
g:
    ...

The exact hexadecimal values are different for every key. Treat this output as sensitive: it includes the private component. Do not paste it into a ticket or terminal recording. Without -noout, OpenSSL also writes the encoded key to standard output, which is easy to overlook when the terminal is being logged.

If the input is encrypted, OpenSSL prompts for its pass phrase. For a non-interactive job, -passin selects a pass-phrase source, for example -passin file:/path/to/passphrase. Protect that file and its permissions; putting a secret directly in a process argument can expose it to local process inspection.

3. Export only the public key

Derive a separate public-key file from the private key:

$ openssl dsa -in private.pem -pubout -out public.pem
read DSA key
writing DSA key
$ openssl dsa -in public.pem -pubin -text -noout
read DSA key
Public-Key: (1024 bit)
pub:
    ...

-pubout changes the output to a public key. -pubin tells the next invocation that its input is public rather than private. OpenSSL also selects public-key handling automatically when the input is recognised as a public key, but stating -pubin makes scripts and troubleshooting clearer. The output file contains no private component, but still verify its destination before sharing it.

Checkpoint

The second command must read public.pem without asking for a private-key pass phrase. If it fails, check that the first command completed and that the file is readable.

4. Convert PEM and DER without overwriting the source

PEM is the default output format. To produce a DER copy, name a new output file:

$ openssl dsa -in private.pem -outform DER -out private.der
read DSA key
writing DSA key
$ openssl dsa -inform DER -in private.der -noout -text
read DSA key
Private-Key: (1024 bit)
priv:
    ...

Use -inform DER when a later command reads the binary file. For a PEM conversion, omit -outform or specify -outform PEM. The input format can be supplied explicitly with -inform PEM when that removes ambiguity.

Do not make the output filename the same as the input filename. The manual explicitly warns against that, and a failed conversion can leave you without a trustworthy original. If you need to replace a managed key, write a new file, verify it, set its ownership and permissions as appropriate for the service, then make a separate, recoverable backup before an approved rename. This guide does not alter service configuration.

5. Choose private-key encryption deliberately

If you provide no encryption option, the output private key is unencrypted. That can remove a pass phrase, but it also means possession of the file is enough to use the key:

$ openssl dsa -in encrypted.pem -out unencrypted.pem
Enter pass phrase for encrypted.pem:
read DSA key
writing DSA key
$ head -1 unencrypted.pem
-----BEGIN DSA PRIVATE KEY-----

This is a security-sensitive conversion. Restrict access to unencrypted.pem, use it only where an unencrypted key is genuinely required, and remove it through your normal secure file-handling process after the consumer has been migrated. Recovery is to keep the original encrypted file and discard the new unencrypted copy before it is used.

To add or change the traditional PEM pass phrase, select a cipher such as -aes256 and provide the output pass phrase interactively:

$ openssl dsa -in private.pem -aes256 -out encrypted-new.pem
Enter PEM pass phrase:
Verifying - Enter PEM pass phrase:
read DSA key
writing DSA key
$ head -2 encrypted-new.pem
-----BEGIN DSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED

The manpage lists AES, ARIA, Camellia, DES and IDEA options, and says they apply only to PEM output. It also warns that this command uses the traditional SSLeay-compatible private-key encryption format. For new applications, use openssl pkcs8 and the PKCS#8 format instead of creating another legacy encrypted DSA file. Never use a real pass phrase in shell history or a copied example.

6. Compare a key's public value when troubleshooting

-modulus prints the public key component. It is useful for checking whether two private-key files correspond without printing every parameter:

$ openssl dsa -in private.pem -modulus -noout
read DSA key
Public Key=7F6616094C5508F2...

Compare the complete value, not the shortened display above. The command reports a public value, but treat command output as sensitive until you understand the surrounding system and logs. A mismatch means the files are not the same DSA key; it does not prove that either file is suitable for a particular service.

Done means

  • You confirmed the OpenSSL version and the dsa subcommand.
  • You inspected a key with -text -noout without accidentally reprinting its encoding.
  • You wrote public, DER or re-encrypted copies to new filenames and verified them.
  • You know whether each private-key output is encrypted and have kept the original until migration is complete.
  • You did not overwrite a source key or expose a real pass phrase in a command example.