{{ summaryPlainText }}
RSA key conversion inputs
Private key material and passphrases are never added to the shareable URL.
{{ inputFeedback }}
Auto resolves from the parsed key material. Encrypted output is always an explicit choice.
Use the input passphrase for encrypted source material or the new passphrase for encrypted output.
{{ passphraseVisible ? 'Passphrase is visible.' : 'Passphrase is hidden.' }}
Use 48-76 characters only when the receiving importer requires a particular wrap.
characters
Off accepts ordinary line breaks; on requires clean base64 payload text.
{{ strict_base64 ? 'On' : 'Off' }}
{{ textExportAnnouncement }}
{{ values.pem_text }}
{{ tableExportAnnouncement }}
RSA key identity and conversion details
FieldValueMeaningCopy
{{ row.label }}{{ row.value }}{{ row.note }}
{{ tableExportAnnouncement }}
RSA PEM wrapper compatibility for the parsed key
WrapperMaterialStatusOperational noteCopy
{{ row.label }}{{ row.material }}{{ row.status }}{{ row.note }}
{{ chartExportAnnouncement }}
{{ summaryAnnouncement }}

A PEM header is more than decoration. RSA PRIVATE KEY, PRIVATE KEY, ENCRYPTED PRIVATE KEY, PUBLIC KEY, and RSA PUBLIC KEY tell an importer which binary structure sits inside the base64 text. Two files can carry the same RSA identity and still be accepted by different software because their wrappers differ.

RSA PEM wrapper purposes
PEM labelStructureMaterialTypical compatibility role
RSA PRIVATE KEYPKCS#1PrivateRSA-specific private format used by older software.
PRIVATE KEYPKCS#8PrivateGeneric unencrypted private-key container with an algorithm identifier.
ENCRYPTED PRIVATE KEYEncrypted PKCS#8PrivatePassword-protected private container for storage or transfer.
PUBLIC KEYSubjectPublicKeyInfoPublicGeneric public wrapper used by X.509 and many import APIs.
RSA PUBLIC KEYPKCS#1PublicRSA-specific public structure expected by some legacy consumers.

Rewrapping a key does not create a new modulus or exponent. Private input contains enough information to produce either private or public wrappers. Public input cannot be turned into private material because the private exponent and prime factors are absent.

PEM is textual armor around Distinguished Encoding Rules (DER) bytes. Changing line width changes only the base64 layout. Changing from PKCS#1 to PKCS#8 or SPKI changes the DER container, but a modulus-based digest can still confirm that the RSA public identity stayed the same.

Encryption is another container property. A passphrase-protected private PEM reduces exposure if the file is copied without the password, while an unencrypted private key may be required for unattended service startup. Neither choice replaces restricted storage, access control, audit logs, backups, and key rotation.

Successful parsing and conversion prove format compatibility only. They do not validate a certificate chain, prove key ownership, check whether the private and public halves belong to a particular certificate, or decide whether the RSA size meets an organization's current policy.

How to Use This Tool:

Identify the material you have and the exact PEM label required by the receiving system before selecting an output wrapper.

  1. Paste one supported RSA PEM block or load one local PEM, key, public-key, or text file. Enter the passphrase when the source is encrypted.
  2. Leave Output PEM on Auto by key material for SPKI public output from a public key or unencrypted PKCS#8 output from a private key.
  3. Choose an explicit target when the importer names one. Private targets require private input; public targets can be built from either public or private input. Encrypted PKCS#8 also requires a passphrase.
  4. Review Key identity and Wrapper readiness. Confirm the input label, public or private material, key size, exponent, modulus digest, SPKI pin, and selected output label.
  5. Adjust the 48 to 76 character PEM wrap or enable strict base64 parsing only for a known importer requirement, then copy or download the complete PEM artifact.

Interpreting Results:

The output header is the immediate compatibility result. PUBLIC KEY and RSA PUBLIC KEY contain public material. The three private labels contain secret material and need private-key handling even when the output is passphrase protected.

The modulus SHA-256 digest identifies the unsigned RSA modulus. The SPKI pin hashes the canonical RSA SubjectPublicKeyInfo DER and encodes the digest as base64. Matching values help show that two wrappers carry the same public identity, but they do not compare private-key encryption settings, filenames, certificate metadata, or trust.

Treat Generated as a wrapper state, not a security approval. A receiving application should parse the exported PEM, and production workflows should compare its public identity with the expected certificate or deployment record.

Technical Details:

RSA wrapper conversion parses the PEM boundary, decodes base64 into DER, extracts the modulus and exponent plus private CRT values when present, then serializes those same values into the requested structure. The RSA algorithm object identifier is checked in generic PKCS#8 and SPKI input so a non-RSA key is not mislabeled.

Transformation Core:

RSA PEM wrapper transformation rules
TargetDER contentRequirementPEM label
PKCS#1 privateRSA version, modulus, public and private exponents, primes, and CRT exponents and coefficientPrivate RSA inputRSA PRIVATE KEY
PKCS#8 privatePrivateKeyInfo with RSA algorithm identifier and embedded PKCS#1 private structurePrivate RSA inputPRIVATE KEY
Encrypted PKCS#8Password-encrypted PKCS#8 private informationPrivate RSA input and nonempty passphraseENCRYPTED PRIVATE KEY
SPKI publicRSA algorithm identifier and a bit string containing the PKCS#1 public structurePublic or private RSA inputPUBLIC KEY
PKCS#1 publicSequence containing the modulus and public exponentPublic or private RSA inputRSA PUBLIC KEY

The conversion path is structural: PEM text to DER, DER to RSA values, RSA values to the selected DER wrapper, then DER back to base64-armored PEM. A public target discards private values from the output while preserving the modulus and exponent.

Rule Core:

RSA parsing and output selection rules
DecisionRuleFailure condition
Auto targetPrivate input becomes unencrypted PKCS#8; public input becomes SPKI.None after a supported key parses.
Private targetRequire the private exponent, primes, and CRT values.Public-only input or an unsupported multi-prime private key is rejected.
Encrypted inputDecrypt encrypted PKCS#8 or legacy encrypted PKCS#1 with the supplied passphrase.A missing or incorrect passphrase stops conversion.
Encrypted outputRequest AES-256 password encryption with 100,000 derivation iterations and a 16-byte salt.A missing passphrase or unavailable cryptographic runtime stops export.
Strict base64Require every nonblank payload line to contain only base64 characters and final padding.Whitespace inside a payload line or non-base64 characters are rejected before DER parsing.
PEM wrapNormalize output width to a multiple of four from 48 to 76 characters.Line width never changes decoded DER bytes.

PKCS#1 private parsing requires the conventional two-prime version and at least the nine core integers. SPKI and PKCS#8 parsing verify the RSA algorithm identifier before reading the embedded key. One complete PEM block with matching boundaries is accepted; unrelated bundles and trailing DER data are rejected.

Key size is the bit length of the unsigned modulus, and the public exponent is rendered as a decimal integer. The modulus digest is SHA-256 over the unsigned modulus bytes. The SPKI pin is SHA-256 over canonical SPKI DER followed by ordinary base64 encoding.

Source PEM is limited to 65,536 characters and passphrases to 4,096 characters. The parser accepts PKCS#1 public and private, unencrypted PKCS#8 private, SPKI public, encrypted PKCS#8 private, and supported legacy encrypted RSA private PEM. It does not accept OpenSSH private keys, PPK, JWK, PKCS#12, certificates, or raw DER input.

Security and Privacy Notes:

Source PEM, passphrases, and converted PEM remain in the browser and are excluded from shareable URL state. Copied or downloaded private material still needs secure handling outside the page.

  • Prefer encrypted PKCS#8 when the receiving system supports it and the passphrase can be stored separately and recovered reliably.
  • If an automated service requires unencrypted private PEM, protect it with restrictive permissions, secret storage, access logging, and a rotation plan.
  • Keep the trusted original until the destination parses the converted key and its public identity matches the expected certificate or deployment record.