RSA Cryptosystem: Public RSA Key Example & Asymmetric Mechanics
The rsa key system, invented by Ron Rivest, Adi Shamir, and Leonard Adleman in 1977, forms the foundational infrastructure for internet trust, HTTPS TLS certificates, and SSH key authentication. An rsa key pair consists of two mathematically coupled components: an rsa public key and an rsa private key.
When someone encrypts data with your rsa public key private key pair, only the holder of the matching private key can decrypt it. Conversely, signing a payload with your private key allows anyone holding your public key to verify its authentic signature.
Public RSA Key Example & Structure
Below is a standard public rsa key example encoded in Base64 SubjectPublicKeyInfo (SPKI) PEM format:
-----BEGIN PUBLIC KEY-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0rK6+kF29oJ3xVf5d1xP
Y6K7mQ8w3nL2p4s5t6u7v8w9x0y1z2a3b4c5d6e7f8g9h0i1j2k3l4m5n6o7p8q9
r0s1t2u3v4w5x6y7z8a9b0c1d2e3f4g5h6i7j8k9l0m1n2o3p4q5r6s7t8u9v0w1
x2y3z4a5b6c7d8e9f0g1h2i3j4k5l6m7n8o9p0q1r2s3t4u5v6w7x8y9z0a1b2c3
d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z6a7b8c9d0e1f2g3h4i5
j6k7l8m9n0o1p2q3r4s5t6u7v8w9x0y1z2a3b4c5d6e7f8g9h0i1j2k3l4m5n6o7
-----END PUBLIC KEY-----
OpenSSL Generate RSA Key: Terminal CLI Commands
To automate cryptographic setups in CI/CD pipelines or Linux servers, you can execute openssl generate rsa key commands directly in your terminal:
# 1. Generate RSA Private Key (2048-bit PKCS#1)
openssl genrsa -out private_key.pem 2048
# 2. Extract Matching RSA Public Key
openssl rsa -in private_key.pem -pubout -out public_key.pem
# 3. How to create RSA keys for SSH authentication:
ssh-keygen -t rsa -b 4096 -C "developer@company.com"
# 4. View ASN.1 decoded key details
openssl rsa -in private_key.pem -text -noout
Choosing the Right Modulus Size: 2048-bit vs 4096-bit
| Modulus Size |
Security Equivalent |
NIST Recommendation |
Performance Overhead |
Primary Use Case |
1024 bits |
80-bit symmetric |
Disallowed / Deprecated |
Minimal |
Testing / Legacy backwards compatibility |
2048 bits |
112-bit symmetric |
Acceptable through 2030+ |
Standard (Fast) |
HTTPS certificates, SSH keys, Git commit signing |
4096 bits |
128-bit symmetric |
High Security / Military Grade |
~4x slower signing |
Root Certificate Authorities, long-term archival |
Frequently Asked Questions: RSA Cryptography
How does this browser-based rsa keygen protect my private key?
This tool uses crypto.subtle.generateKey, an isolated browser engine implementation written in native C++. The mathematical primes and private key material never touch external network packets, keeping your rsa public private key generation completely offline and air-gapped.
Can I convert the generated public key into OpenSSH authorized_keys format?
Yes. While PEM is the universal standard for SSL/TLS, web servers, and OpenSSL, you can convert PEM public keys to OpenSSH format using the command ssh-keygen -i -m PKCS8 -f public_key.pem.
Why is the exponent always 65537?
The number 65537 (Fermat number F4, or 2^16 + 1) is chosen internationally because its binary representation (10000000000000001) contains only two 1-bits. This makes modular exponentiation fast while avoiding Coppersmith's attack on low exponents like 3.
What is the difference between RSA and ECC (Elliptic Curves)?
RSA relies on the computational difficulty of factoring the product of two large prime numbers. Elliptic Curve Cryptography (ECC, like Ed25519) relies on the discrete logarithm problem on elliptic curves, providing comparable 128-bit security with much smaller 256-bit keys.