Home / Alt manpages / openssl-dsaparam(1ssl)

  • openssl-dsaparam(1ssl)
  • OpenSSL command
  • linux

Generate and inspect DSA parameters with OpenSSL dsaparam

You will finish with a PEM file containing DSA parameters, a readable inspection of those values, and, if you really need one, a private key generated from the same parameters. The examples were checked with OpenSSL 3.6.1 on Linux. Allow about ten minutes, plus the time needed for parameter generation.

DSA parameter generation is deliberately expensive compared with reading an existing file. The resulting parameters can be reused for several keys, but DSA is a legacy algorithm. Use it only when an existing protocol or application requires it. For a new design, check whether it supports a modern algorithm before creating new DSA material.

1. Check the installed command

Start with read-only checks. They do not need elevated privileges:

$ openssl version
OpenSSL 3.6.1 27 Jan 2026 (Library: OpenSSL 3.6.1 27 Jan 2026)
$ openssl dsaparam -help

The installed binary reports 3.6.1 here, while the local packaged manual has a 3.0.13 header. That difference matters: the binary help also lists -quiet, -provparam and an optional numqbits argument. Prefer the installed help when checking options on your own host, and do not assume that a command copied from another OpenSSL release has identical details.

Checkpoint: make sure the command resolves to the OpenSSL installation you intend to use:

$ command -v openssl
/usr/bin/openssl

Your path may differ. If it points into a custom installation, run the version check again before continuing.

2. Generate a PEM parameter file

Choose a new destination and make the bit length explicit. This example uses 1024 bits because it completed successfully with the installed command:

$ openssl dsaparam -out /tmp/dsa-params.pem 1024
Generating DSA parameters, 1024 bit long prime
This could take some time

The progress characters and exact wording vary. A successful exit status and a non-empty file are the useful checks:

$ test -s /tmp/dsa-params.pem && echo "parameter file is non-empty"
parameter file is non-empty
$ head -n 1 /tmp/dsa-params.pem
-----BEGIN DSA PARAMETERS-----

Do not use an existing important path for the first run. The -out option writes that file, and replacing a parameter file can break later consumers. If you need a permanent location, generate in a temporary path, inspect it, then move it into place during your normal change process.

3. Inspect the parameters without rewriting them

Ask dsaparam for human-readable values and suppress the encoded PEM output. State the input format explicitly so a script does not depend on format detection:

$ openssl dsaparam -inform PEM -in /tmp/dsa-params.pem -text -noout
DSA-Parameters: (1024 bit)
P:
    ... hexadecimal values ...
Q:
    ... hexadecimal values ...
G:
    ... hexadecimal values ...

The actual hexadecimal values are random and will not match this abbreviated example. The important checks are the reported bit length and the presence of P, Q and G. -text is for inspection; -noout prevents another encoded copy being written to standard output.

Checkpoint: if this command fails, check the first PEM marker and the file permissions before trying sudo. Elevated privileges do not repair a truncated file or a wrong format.

4. Generate a key from the parameters

Only do this if the consuming application needs a DSA private key. The operation creates secret material, so protect the destination and do not paste the key into logs or tickets:

$ umask 077
$ openssl dsaparam -inform PEM -in /tmp/dsa-params.pem -genkey -noout -out /tmp/dsa-key.pem
$ head -n 1 /tmp/dsa-key.pem
-----BEGIN PRIVATE KEY-----

With -genkey, the command generates a key using the specified or generated parameters. In this workflow, -noout is intentional: it suppresses the parameter encoding so the output file contains only the private key. Check its permissions:

$ stat -c '%A %n' /tmp/dsa-key.pem
-rw------- /tmp/dsa-key.pem

If you created the key by mistake, remove it only after confirming that no application needs it and that no backup is required. Destruction is irreversible. If the key has been exposed, treat it as compromised and replace it wherever it was installed.

5. Convert a copy to DER when a consumer requires it

PEM is the default output format. DER is binary, so convert a copy rather than overwriting the readable source:

$ openssl dsaparam -inform PEM -in /tmp/dsa-params.pem \
    -outform DER -out /tmp/dsa-params.der
$ file /tmp/dsa-params.der
/tmp/dsa-params.der: data

The output is binary and is not suitable for a text editor. Format support can vary between OpenSSL releases and consumers. On the OpenSSL 3.6.1 installation used for this guide, the generated DER file was written successfully but the same dsaparam command rejected it when read back with -inform DER. Treat that as a compatibility warning: test the exact DER file with the application that requires it, and keep the verified PEM source until that test passes.

6. Keep the workflow reproducible

Record the OpenSSL version, bit length, format and destination in the change or run notes. Do not rely on random progress output as evidence that a file is valid. A repeatable inspection command is:

$ openssl version
$ openssl dsaparam -inform PEM -in /tmp/dsa-params.pem -text -noout | sed -n '1,5p'

The -in file must not be the same as the -out file. The manual explicitly warns against that arrangement. When a command fails, preserve the original parameter file, capture the error, and test a new destination rather than repeatedly overwriting the input.

Done means

  • You confirmed the OpenSSL version and the local dsaparam -help output.
  • You generated a new, non-empty PEM parameter file without overwriting an existing one.
  • You inspected the bit length and the P, Q and G values.
  • You generated a private key only when a legacy consumer required it, with restrictive permissions.
  • You kept PEM as the verified source when DER compatibility was uncertain.
  • You did not use elevated privileges unless the chosen destination actually required them.