RSA Key Generator
Generate RSA public and private key pairs in PEM format. Server-side generation using OpenSSL — keys are never stored.
Frequently Asked Questions
What are RSA keys used for?
RSA key pairs are used for public-key cryptography: encrypting data that only the private key holder can decrypt, digitally signing messages to prove authenticity, and authenticating SSH connections to servers without passwords. The public key can be shared freely while the private key must be kept secret.
What key size should I generate?
2048-bit RSA is the current minimum recommended and is suitable for most uses. 4096-bit keys provide stronger security for high-value applications. For new projects, consider ECDSA keys instead — 256-bit ECDSA provides equivalent strength to 3072-bit RSA with much better performance.
Is it safe to generate RSA keys in a browser tool?
The key generation uses the browser's Web Crypto API, which implements cryptographically secure random number generation. Keys are generated entirely on your device and never transmitted to any server. For production use on critical systems, generating keys using OpenSSL on a trusted machine is considered best practice.
What key size should I use?
2048-bit RSA is the current standard recommended by NIST and is used by most SSL certificates and SSH keys. 4096-bit provides extra security at the cost of slower operations — use it for long-term key storage. 1024-bit is obsolete and should not be used.
What is RSA used for?
RSA is used for SSL/TLS certificates, SSH authentication, email encryption (PGP/GPG), code signing and secure key exchange. The public key encrypts data; only the private key can decrypt it.
What is PEM format?
PEM (Privacy Enhanced Mail) is a Base64-encoded format for cryptographic keys and certificates, wrapped in header and footer lines like -----BEGIN RSA PRIVATE KEY-----. It is the most widely supported format for OpenSSL, nginx, Apache and most programming languages.