Tooleux

Sign a message with an RSA private key. Output is a Base64 or Hex signature.

Runs in your browser. Nothing leaves your device.
Sign a message with an RSA private key. Free, offline, runs entirely in your browser. Read more Show less

What is an RSA signature?

An RSA signature proves that a message was produced by the holder of the private key. The signer applies a hash function and a padding scheme to the message, then raises the result to the private exponent modulo the modulus. Anyone with the public key can verify it.

This tool uses RSA-PSS with SHA-256 by default, which is the recommended scheme for new systems. PKCS#1 v1.5 is also available for compatibility with older libraries.

How to use

Paste an RSA private key in PEM format. Type or paste the message. Choose the hash and padding scheme. Click Sign.

The output is a raw signature, shown as Base64 by default. To verify, use the Verify tool with the matching public key.

FAQ

Is the private key sent anywhere?

No. Signing is done entirely in your browser using Web Crypto.

PSS vs PKCS#1 v1.5

PSS is provably secure and the current recommendation (RFC 8017). PKCS#1 v1.5 is older but still widely supported. Use PSS unless you specifically need compatibility.

What signature size should I expect?

Equal to the modulus size: 256 bytes for 2048-bit, 384 for 3072-bit, 512 for 4096-bit.

How to verify with openssl

The output is a standard RSASSA-PSS or PKCS#1 signature. To verify it with the openssl command line:

  1. Save the signature to sig.bin and the message to message.txt.
  2. Save the private key to key.pem and extract the public key: openssl rsa -in key.pem -pubout -out pub.pem.
  3. Run openssl dgst -sha256 -verify pub.pem -signature sig.bin message.txt.
  4. For PKCS#1 v1.5 padding, add -sigopt rsa_padding_mode:pkcs1. For PSS, use -sigopt rsa_padding_mode:pss -sigopt rsa_pss_saltlen:32.
Private key (PEM)
Message
Signature