Language: English

tools / rsa

rsa/

Encrypt with an RSA public key and decrypt with the private key, or encrypt with the private key and decrypt with the public key. Padding, key format, input / output format and charset are all configurable, and your keys never leave the browser.

Plaintext

Key

Ciphertext

History

Each successful encryption or decryption is saved automatically. The latest 20 are kept, only in this device's browser. Keys are never saved, but decrypted plaintext is, so clear the history when you are done on a shared computer.

AES, DES and RSA: what they are and how they differ

AES and DES are symmetric ciphers: the same key encrypts and decrypts, like one key that both locks and unlocks a door. They are fast and suit large amounts of data; the hard part is getting that key to the other side safely.

DES is an old standard from the 1970s with an effective key of only 56 bits, which dedicated hardware or computer clusters can now brute-force, so it is only for talking to legacy systems that still use it. AES replaced DES as the standard. It uses 128, 192 or 256-bit keys, has no practical attack today, and is the default choice for encrypting data.

RSA is asymmetric: there is a key pair. The public key can be given to anyone and is used to encrypt; the private key stays with you and is used to decrypt, like a mailbox anyone can drop letters into but only you can open. No shared key has to be agreed in advance, but RSA is slow and can only encrypt a few hundred bytes at a time. Real systems often combine the two: RSA encrypts a randomly generated AES key for the other side, and AES encrypts the actual data.

How much data can RSA encrypt at once?

RSA can only encrypt a small block of data at a time, limited by the key size and padding. With PKCS1Padding the limit is the key size in bytes minus 11, which is 245 bytes for a 2048-bit key. With OAEP it is the key size in bytes minus twice the hash length minus 2, which is 190 bytes for a 2048-bit key with SHA-256. Longer data is usually encrypted with AES, and RSA is used to encrypt the AES key.

Mapping to Java Cipher names

Padding names match Java's Cipher: for RSA/ECB/PKCS1Padding choose PKCS1Padding; for RSA/ECB/OAEPWithSHA-256AndMGF1Padding choose the third option, since Java uses SHA-1 for MGF1 by default; if you set custom hashes with OAEPParameterSpec, choose OAEPPadding and pick the OAEP hash and MGF1 hash separately. Charsets follow Java's rules too, for example UTF-16 is encoded big-endian with a leading FE FF.

Why is the ciphertext different every time?

When encrypting with a public key, both PKCS1Padding and OAEP add random bytes to the padding, so the same text gives a different ciphertext each time, and every one of them decrypts with the private key. This is expected. Private-key encryption uses fixed padding, so its result is always the same. OAEP only works for public-key encryption and private-key decryption.

Supported key formats

PEM keys can be BEGIN PUBLIC KEY, BEGIN RSA PUBLIC KEY, BEGIN PRIVATE KEY or BEGIN RSA PRIVATE KEY, and you can also paste just the Base64 body. A hex key is the same content in hexadecimal. Password-protected private keys must be decrypted first. With the key type set to public key you can paste a private key as well, and its public part will be used.

FAQ

What should I do when decryption fails with "the key does not match, or the key type or padding is wrong"?

Check three things in turn. First, whether the key is the pair of the public key used to encrypt, since content encrypted with a public key can only be opened by its matching private key. Second, the key type must be set to private key. Third, the padding must match the encrypting side; with OAEPPadding, the OAEP hash and the MGF1 hash must also match. Finally confirm the input format, because mixing up hex and base64 also makes decryption fail.

What should I do when the key format is rejected, or it says CERTIFICATE is not supported?

First make sure "Key format" matches what you pasted: choose pem for text starting with -----BEGIN and hex for a long string of hexadecimal; when it is wrong you usually get a message saying which to switch to. The PEM must hold an RSA public or private key, and a certificate (BEGIN CERTIFICATE) cannot be used directly; you can extract the public key first with openssl x509 -in cert.pem -pubkey -noout. When a certificate and a key are pasted together, the key block is picked out automatically.

My private key has a password and it says to decrypt it first. What should I do?

Password-protected private keys are not supported (BEGIN ENCRYPTED PRIVATE KEY, or a Proc-Type: 4,ENCRYPTED line in the PEM header). Remove the password on your own machine first and then paste the key, for example with openssl rsa -in original-file -out new-file, entering the password when prompted. The resulting file is an unprotected private key, so handle it with care once you are done.

It says the content is over the limit. How many Chinese characters can I encrypt?

The limit counts bytes, not characters. A 2048-bit key with PKCS1Padding allows at most 245 bytes, and one Chinese character takes 3 bytes in UTF-8, so about 81 characters; with the GBK charset a character takes 2 bytes, so about 122. When encrypting, after you paste a key the Key panel shows "max N bytes per encryption" for the current key and padding. Going over gives an error, and the tool does not split the content into chunks automatically.

How do I decrypt data encrypted with JSEncrypt or Web Crypto in the browser?

JSEncrypt uses PKCS1Padding and outputs Base64, so choose PKCS1Padding here and set the input format to base64. The browser's Web Crypto RSA-OAEP uses one hash for both OAEP and MGF1, so choose OAEPPadding here and set the OAEP hash and the MGF1 hash to the same value, for example SHA256 for both. In both cases set the key type to private key.

What does "the ciphertext is longer than the key" or "out of range for this key" mean?

RSA ciphertext is as long as the key in bytes: 256 bytes for a 2048-bit key, which is 512 characters in hex, and never longer. When decrypting, the Key panel shows "N-byte ciphertext" next to its title, so compare that with the byte count next to the input. A ciphertext longer than the key usually means the wrong input format or extra copied content; a value out of range means the ciphertext was not encrypted with the public key paired with this key, so switch to the right key.

Can private-key encryption and public-key decryption be used to sign and verify?

Not directly. Private-key encryption here just applies the private key to your input with PKCS1Padding and does no hashing, whereas a signature such as SHA256withRSA hashes the data first and then wraps the hash in a fixed structure (DigestInfo). So decrypting a standard signature here with the public key gives you that structure, not the original text. To sign or verify, use a library or tool that supports algorithms such as SHA256withRSA.

What does the history store, and is it uploaded?

It lives only in the localStorage of this device's browser and is never uploaded; the page code makes no network requests. One entry is added after each successful encryption or decryption, up to 20 are kept, and anything whose input or result is over 20,000 characters is not recorded. An entry holds the parameters, input and result, plus an 8-character fingerprint derived from the key (the first 8 hex characters of the SHA-256 of the modulus, shown after the # in each entry, used to tell whether it is the same key), but never the key itself, so after clicking "Load" you need to paste the key again. Decrypted plaintext is saved, so on a shared computer click "Clear history" when you are done.