pkeyutl.1s
Perform low-level public key operations
TLDR
SYNOPSIS
openssl pkeyutl [options]
DESCRIPTION
openssl pkeyutl performs low-level public key cryptographic operations including signing, verification, encryption, decryption, key derivation, and key encapsulation/decapsulation (KEM). It is algorithm-agnostic and works with any key type supported by OpenSSL, including RSA, EC, DSA, Ed25519, Ed448, X25519, X448, SM2, and post-quantum algorithms such as ML-DSA and ML-KEM.Unlike higher-level OpenSSL commands, it operates directly on data, offering fine-grained control over padding schemes, digest selection, and key agreement protocols. By default it expects pre-digested input; pass -rawin with -digest to have the tool hash the data itself before operating.For Ed25519 and Ed448, the entire input file is loaded into memory and operated on in a single shot; these algorithms do not support pre-hashing.
PARAMETERS
-sign
Sign the input data and output the signed result. Requires a private key.-verify
Verify the input data against a signature file specified with -sigfile.-verifyrecover
Recover the original data from a signature. RSA only.-encrypt
Encrypt the input data using a public key.-decrypt
Decrypt the input data using a private key.-derive
Derive a shared secret using a peer public key (ECDH/DH).-encap
Encapsulate a shared secret to a peer's public key (KEM operations, e.g. ML-KEM).-decap
Decapsulate to recover a shared secret (KEM operations, e.g. ML-KEM).-in FILE
Input file (stdin if not specified).-out FILE
Output file (stdout if not specified).-secret FILE
Output file for the shared secret in encapsulation/decapsulation operations.-inkey FILE|URI
Input key file. Private key by default; use -pubin or -certin to supply a public key.-sigfile FILE
Signature file, required for -verify operations.-peerkey FILE
Peer public key file, used with -derive for ECDH/DH key agreement.-pubin
Treat the key supplied via -inkey as a public key.-certin
Treat the key supplied via -inkey as a certificate from which the public key is extracted.-keyform PEM|DER|P12
Format of the key file. Default is PEM.-peerform PEM|DER|P12
Format of the peer key file. Default is PEM.-passin ARG
Password source for encrypted private keys (e.g. `pass:secret`, `env:VAR`, `file:path`).-rawin
Treat input as raw unhashed data. The tool will hash it internally using the algorithm specified by -digest. Required for Ed25519/Ed448 and recommended for RSA-PSS signing.-digest ALGORITHM
Hash algorithm to apply when -rawin is set (e.g. `sha256`, `sha512`). Defaults to SHA-256 for RSA/DSA/ECDSA and SM3 for SM2.-pkeyopt opt:value
Set an algorithm-specific option. May be repeated. Common options:
- `rsapaddingmode:pkcs1|oaep|pss|none` — RSA padding mode (default: `pkcs1`)
- `rsaoaepmd:digest` — Hash for OAEP label (default: `sha1`)
- `rsamgf1md:digest` — MGF1 digest for PSS or OAEP
- `rsapsssaltlen:len|digest|max|auto` — PSS salt length
- `distid:string` — SM2 distinguishing ID (must match for sign/verify)-kdf ALGORITHM
Key derivation function to use (e.g. `TLS1-PRF`, `HKDF`).-kdflen LENGTH
Output length in bytes for the KDF operation.-rev
Reverse the input buffer byte order before processing. Incompatible with -rawin.-hexdump
Hex dump the output data.-asn1parse
Parse and display the output as ASN.1.
CAVEATS
Part of OpenSSL. Input size for non-raw operations is limited to `EVPMAXMDSIZE` (64 bytes); use **-rawin** for arbitrary-length inputs. RSA PKCS#1 v1.5 decryption applies implicit rejection (returning deterministic random plaintext on padding failure) to mitigate Bleichenbacher attacks. Use OAEP padding (`-pkeyopt rsapadding_mode:oaep`) for new RSA encryption applications. Ed25519/Ed448 sign and verify load the whole file into memory.
HISTORY
openssl pkeyutl provides public key operations across all algorithms and supersedes the older rsautl subcommand for RSA-specific work. KEM operations (-encap/-decap) and post-quantum algorithm support were added in OpenSSL 3.x.
SEE ALSO
openssl(1), openssl-pkey(1), openssl-genpkey(1), openssl-dgst(1)
