Home / Alt manpages / openssl-rsa(1ssl)

  • openssl-rsa(1ssl)
  • OpenSSL command
  • linux

Safely inspect and convert RSA keys with openssl rsa

You will finish with a checked RSA private key, a separate public key, and repeatable commands for moving between PEM and DER. The examples use OpenSSL 3.6.1, installed from the openssl package. Allow about fifteen minutes if the key files already exist. You need a shell and read access to the source key. No command in this guide needs elevated privileges unless the key itself is protected by file permissions.

Work on copies or write to new filenames. Private keys are security-sensitive, and openssl rsa can deliberately write an unencrypted private key when no encryption option is given. The command will not protect you from choosing a weak output location. Keep the source file until the new file has been checked and any dependent service has been tested.

1. Check the private key before changing it

Set a shell variable to the real path of your key, then ask OpenSSL to check its internal RSA consistency without printing the key:

key=/path/to/private-key.pem
openssl rsa -in "$key" -check -noout

An intact private key prints:

RSA key ok

The command reads an encrypted key by prompting for its pass phrase. If the file is not PEM, specify the input format explicitly with -inform DER, -inform P12 or another format supported by this installed command. Do not guess from a filename extension. OpenSSL reads standard input when -in is omitted, which can make an accidental paste or pipeline harder to review.

Checkpoint: stop here if the check fails. Confirm the path, input format and pass phrase first. Do not overwrite the original while trying different options.

2. Export a public key into a new file

Extract the public portion of the private key with -pubout:

openssl rsa -in "$key" -pubout -out public-key.pem

On OpenSSL 3.6.1, a successful run writes a PEM public key beginning with:

-----BEGIN PUBLIC KEY-----

Verify that the result can be read as a public key:

openssl rsa -pubin -in public-key.pem -text -noout

The -pubin option matters when the input is public-only. Without it, the command expects a private key by default. The -text output includes key components, so keep it out of logs and tickets. Use -noout when you want the readable details without another encoded key block.

3. Convert PEM to DER without replacing the source

PEM is text with a base64 wrapper. DER is binary. Write the converted key to a different path:

openssl rsa -in "$key" -outform DER -out private-key.der

Confirm that the binary file can be read back by declaring its format:

openssl rsa -inform DER -in private-key.der -check -noout

Expect RSA key ok again. DER output is not suitable for a text editor or a PEM-only configuration field. Conversely, a PEM output file is the default when -outform is omitted. If another program requires the traditional PKCS#1 private-key wrapper rather than the OpenSSL 3 default PKCS#8 wrapper, add -traditional while writing a private PEM file. Confirm the receiving program's requirement before choosing it.

4. Add or change private-key encryption

To create an encrypted PEM copy, choose a cipher such as AES-256:

openssl rsa -in "$key" -aes256 -out private-key-encrypted.pem

OpenSSL prompts for the new pass phrase. It does not echo the pass phrase, and it writes a PEM file that begins with an encrypted private-key heading. Check the result by supplying the pass phrase interactively:

openssl rsa -in private-key-encrypted.pem -check -noout

To automate a non-interactive check, use a password source appropriate to your secret-management system with -passin. The documented argument forms include sources such as a file or environment variable. Avoid putting a real pass phrase directly in a shell command: it can enter shell history, process listings or CI logs. The same principle applies to -passout when creating encrypted output.

Warning: omitting every encryption option writes a plain-text private key. That is how the command can remove a pass phrase, but it also creates a copy that anyone who can read the file can use. If you intentionally need that form, restrict its permissions, test the consumer, and remove the unencrypted copy securely after confirming the replacement. Do not use sudo to make a key readable unless the service's ownership and permissions require it.

5. Diagnose the common format and output mistakes

  • Pass phrase errors: rerun the read-only -check command and verify that you are using -passin for the input key, not -passout for the new file.
  • Public key rejected: add -pubin when reading a public PEM. Use -RSAPublicKey_in only for the older RSAPublicKey structure, which is different from the usual SubjectPublicKeyInfo output produced by -pubout.
  • Binary output looks corrupt: that is normal for DER. Read it with -inform DER; do not open it in an editor or paste it into a text configuration file.
  • Output is unexpectedly plain text: encryption is opt-in for this command. Recreate the output with -aes256 or another permitted cipher, then verify it before replacing any consumer's key.
  • The output file already exists: choose a new temporary name, compare and check it, then arrange the service's changeover. Never set the output filename equal to the input filename; the manpage explicitly warns against it.

The -modulus option prints the RSA modulus and can help compare whether two RSA keys belong together, but treat the resulting value as sensitive operational data. The deprecated -engine option is not part of a new setup; OpenSSL documents it as deprecated since version 3.0. The newer openssl pkey command can perform these operations for RSA and other public-key types, but use the command that matches the surrounding procedure and its format expectations.

Done means

  • The source private key passed openssl rsa -check -noout.
  • The public key was exported to a different file and read back with -pubin.
  • Any PEM to DER conversion was checked with the matching -inform DER option.
  • Encrypted output was tested with its pass phrase before any service change.
  • No source key was overwritten, and any plain-text private-key copy has a deliberate owner, permission and removal plan.