Public-key inspection

SSH public keys: wire structure, SHA256 fingerprints and trust

A public-key line contains an algorithm, Base64 wire blob and optional comment. The comment may be useful to a person, but it is not part of the fingerprint or evidence of ownership.

Content updated: · Maintainer and corrections

Use the public .pub line only

This inspector accepts exactly one ordinary OpenSSH RSA, Ed25519 or NIST ECDSA nistp256/384/521 public-key line, at most 32768 UTF-8 bytes. It rejects private-key containers, certificates, DSA, FIDO sk-* keys, known_hosts prefixes and authorized_keys options. Remove options yourself rather than asking the parser to skip restrictions it does not understand.

Standard Base64 may have canonical padding or omit it. URL-safe symbols, non-zero unused bits, malformed lengths and trailing binary bytes are rejected. The embedded algorithm must match the outer label. Comments can contain usernames or internal host details; inputs remain in page memory and do not require a remote host or SSH agent.

Understand what structural checks prove

SSH strings use a four-byte big-endian length. RSA exposes canonical positive mpint exponent and modulus; the reported bit length comes from the modulus without a sign-padding byte. Ed25519 requires exactly 32 public bytes. NIST ECDSA requires the matching curve name and an uncompressed point of 65, 97 or 133 bytes.

These are framing checks, not mathematical validation. The tool does not test RSA factorization, exponent security, Ed25519 subgroup membership or ECDSA curve membership. Equal encoded bit counts across algorithms do not imply equal security. The included Ed25519 example is synthetic public structure and should not be used for login.

Compare fingerprints through a trusted channel

SHA256 fingerprints hash the original decoded SSH wire blob, including its internal algorithm and fields, and display SHA256: followed by unpadded standard Base64. Changing only the comment does not change the digest. OpenSSH uses the same form with ssh-keygen -lf public-key.pub -E sha256.

An expected value must be SHA256: plus 43 canonical Base64 characters without =. A match indicates the supplied public bytes have the expected digest, not who controls the private key, whether a signature is valid or whether login is authorized. Obtain the expected fingerprint independently; comparing a key against a digest delivered by the same untrusted channel adds no independent trust. Web Crypto requires a secure browser context. Editing an input invalidates pending asynchronous work and disables stale exports.

Data provenance

Sources