Home / Alt manpages / openssl-spkac(1ssl)

  • openssl-spkac(1ssl)
  • OpenSSL command
  • linux

Generate and Verify an SPKAC with OpenSSL

You will finish with a Netscape signed public key and challenge (SPKAC) file generated from a private key, a checked signature, and a way to extract the embedded public key. The examples use OpenSSL 3.6.1, which is the installed version at the time of writing.

Allow about fifteen minutes. You need the openssl command and a private key that you are allowed to use. The guide writes only to a temporary working directory. It does not create a certificate, submit anything to a CA, or alter system configuration.

Security boundary

An SPKAC contains a public key, challenge string and signature. It does not contain the private key. Treat the private key as sensitive, and do not paste a real private key into a shell history, ticket or chat.

1. Confirm the installed command

Check the executable and version first. These are read-only commands and do not need elevated privileges:

$ command -v openssl
/home/linuxbrew/.linuxbrew/bin/openssl
$ openssl version
OpenSSL 3.6.1 27 Jan 2026

The relevant subcommand is openssl spkac. It can print an existing SPKAC, verify its signature, output its public key, or create a new SPKAC with -key.

Checkpoint

If openssl version reports an older release, keep its local manual page beside you. Option support and provider behaviour can differ between OpenSSL releases.

2. Prepare a private key without overwriting one

If you already have a suitable private key, use its path in the next step and skip key generation. For a disposable test, create a temporary directory and a 2048-bit RSA key:

$ workdir=$(mktemp -d /tmp/openssl-spkac.XXXXXX)
$ openssl genrsa -traditional -out "$workdir/key.pem" 2048
$ chmod 600 "$workdir/key.pem"
$ ls -l "$workdir/key.pem"
-rw------- 1 ... key.pem

The output from genrsa can vary. The useful check is that the file exists and is readable only by its owner. Do not run this as root unless the key destination genuinely requires it. Keep the temporary directory private while it contains the key.

This guide uses a test key so that it can be discarded. Do not delete a production key as cleanup. If you created the temporary key above, remove the temporary directory after you have completed all checks:

$ rm -rf -- "$workdir"

That cleanup is irreversible for the test key, so do not run it until the later verification step has passed.

3. Generate the SPKAC

Use -key to create the SPKAC, -challenge to include a caller-chosen challenge, and -out to save the configuration-style output:

$ openssl spkac \
    -key "$workdir/key.pem" \
    -digest sha256 \
    -challenge 'demo-2026-09-25' \
    -out "$workdir/spkac.cnf"
$ sed -n '1p' "$workdir/spkac.cnf"
SPKAC=MIIB...

The long value is base64-encoded data and will differ for every key and run. The file normally contains an SPKAC= assignment on one line. A challenge should be fresh and unpredictable when it is used to prevent replay in a real enrolment workflow; the dated value here is only an obvious test label.

Important default: the installed manual says the default signing digest is MD5. The example selects SHA-256 explicitly. Do not accept the default for a new workflow without checking that the relying system deliberately requires it. If an old CA or integration requires another digest, confirm that requirement before generating requests.

4. Inspect the request and challenge

Print the decoded SPKAC without changing the file:

$ openssl spkac -in "$workdir/spkac.cnf"
Netscape SPKI:
  Public Key Algorithm: rsaEncryption
    Public-Key: (2048 bit)
    ...
  Challenge String: demo-2026-09-25
  Signature Algorithm: sha256WithRSAEncryption
      ...

The modulus, signature bytes and line wrapping are specific to your key. Check the challenge and signature algorithm, not the exact byte output. The -in option reads standard input instead when it is omitted, and -out writes standard output when it is omitted.

Checkpoint

Stop here if the challenge is wrong, the file is in the wrong directory, or the algorithm is not acceptable to the receiving system. Correct the generation command and create a new output file rather than editing the base64 by hand.

5. Verify the SPKAC signature

Verification checks that the SPKAC's signature matches the data and public key carried in that SPKAC:

$ openssl spkac -in "$workdir/spkac.cnf" -noout -verify
Signature OK

-verify reports success with the text shown above on this OpenSSL build. A modified challenge, damaged base64 value or incompatible signature should produce an error and a non-zero exit status. Capture the status in a script if verification gates a later action:

$ if openssl spkac -in "$workdir/spkac.cnf" -noout -verify; then
>     echo 'SPKAC verified'
> else
>     echo 'SPKAC verification failed' >&2
>     exit 1
> fi
Signature OK
SPKAC verified

Verification is not certificate validation. It does not establish that a CA trusts the key, that a subject name is present, or that a challenge came from the party you expected. It only checks the SPKAC signature.

6. Extract the public key when needed

Use -noout -pubkey when another tool needs the public key without the descriptive SPKAC text:

$ openssl spkac -in "$workdir/spkac.cnf" -noout -pubkey > "$workdir/public.pem"
$ sed -n '1,2p' "$workdir/public.pem"
-----BEGIN PUBLIC KEY-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A...

The public key is safe to distribute in the ordinary sense, but compare it with the expected key before attaching it to an identity or certificate request. Keep the private key and public key paths distinct. The manual states that -in, -noout, -spksect and -verify are ignored when -key is used, so do not combine generation and verification in one command and assume both operations happened.

7. Clean up without losing evidence

Retain spkac.cnf and public.pem only where your enrolment process requires them. Before deleting the temporary key, confirm that you have copied the SPKAC to the intended protected location and that verification has passed. Then remove the temporary directory:

$ test -s "$workdir/spkac.cnf" && openssl spkac -in "$workdir/spkac.cnf" -noout -verify
Signature OK
$ rm -rf -- "$workdir"

There is no service restart or persistent OpenSSL configuration to undo. If you accidentally generated an SPKAC with an unsuitable digest, discard that SPKAC and regenerate it with an explicitly approved digest. Do not try to repair its encoded value manually.

Done means

  • You confirmed the installed OpenSSL version and used the matching spkac command.
  • You generated an SPKAC from an authorised private key without overwriting an existing key.
  • You supplied a challenge and selected SHA-256 instead of accepting the documented MD5 default.
  • You inspected the challenge and signature algorithm in the decoded output.
  • openssl spkac -noout -verify returned Signature OK.
  • You understand that signature verification is not CA trust or certificate validation.