Skip site navigation (1)Skip section navigation (2)

  
 
  

home | help
OPENSSL-DGST(1ossl)		     OpenSSL		     OPENSSL-DGST(1ossl)

NAME
     openssl-dgst - perform digest operations

SYNOPSIS
     openssl dgst|digest [-digest] [-list] [-help] [-c] [-d] [-debug] [-hex]
     [-binary] [-xoflen length] [-r] [-out filename] [-sign filename|uri] [-key-
     form DER|PEM|P12] [-passin arg] [-verify filename] [-prverify filename]
     [-signature filename] [-sigopt nm:v] [-hmac key] [-hmac-env var]
     [-hmac-stdin] [-mac alg] [-macopt nm:v] [-fips-fingerprint] [-rand files]
     [-writerand file] [-provider name] [-provider-path path] [-provparam
     [name:]key=value] [-propquery propq] [file ...]

DESCRIPTION
     This command output the message digest of a supplied file or files in hexa-
     decimal, and also generates and verifies digital signatures using message
     digests.

     The generic name, openssl dgst, may be used with an option specifying the
     algorithm to be used.  The default digest is sha256.  A supported digest
     name may also be used as the sub-command name.  To see the list of sup-
     ported algorithms, use "openssl list -digest-algorithms"

OPTIONS
     -help
	 Print out a usage message.

     -digest
	 Specifies name of a supported digest to be used. See option -list below
	 :

     -list
	 Prints out a list of supported message digests.

     -c  Print out the digest in two digit groups separated by colons, only rel-
	 evant if the -hex option is given as well.

     -d, -debug
	 Print out BIO debugging information.

     -hexDigest is to be output as a hex dump. This is the default case for a
	 "normal" digest as opposed to a digital signature.  See NOTES below for
	 digital signatures using -hex.

     -binary
	 Output the digest or signature in binary form.

     -xoflen length
	 Set the output length for XOF algorithms, such as shake128 and
	 shake256.  This option is not supported for signing operations.

	 For OpenSSL providers it is required to set this value for shake algo-
	 rithms, since the previous default values were only set to supply half
	 of the maximum security strength.

	 To ensure the maximum security strength of 128 bits, the xoflen for
	 shake128 should be set to at least 32 (bytes). For compatibility with
	 previous versions of OpenSSL, it may be set to 16, resulting in a secu-
	 rity strength of only 64 bits.

	 To ensure the maximum security strength of 256 bits, the xoflen for
	 shake256 should be set to at least 64 (bytes). For compatibility with
	 previous versions of OpenSSL, it may be set to 32, resulting in a secu-
	 rity strength of only 128 bits.

     -r  Output the digest in the "coreutils" format, including newlines.  Used
	 by programs like sha1sum(1).

     -out filename
	 Filename to output to, or standard output by default.

     -sign filename|uri
	 Digitally sign the digest using the given private key.

	 Note that for algorithms that only support one-shot signing (such as
	 Ed25519, ED448, ML-DSA-44, ML-DSA-65 andML-DSA-87) the digest must not
	 be set. For these algorithms the input is buffered (and not digested)
	 before signing. For these algorithms, if the input is larger than 16MB
	 an error will occur.

     -keyform DER|PEM|P12
	 The format of the key to sign with; unspecified by default.  See
	 openssl-format-options(1) for details.

     -sigopt nm:v
	 Pass options to the signature algorithm during sign or verify opera-
	 tions.  Names and values of these options are algorithm-specific and
	 documented in "Signature parameters" in provider-signature(7).

     -passin arg
	 The private key password source. For more information about the format
	 of arg see openssl-passphrase-options(1).

     -verify filename
	 Verify the signature using the public key in "filename".  The output is
	 either "Verified OK" or "Verification Failure".

     -prverify filename
	 Verify the signature using the private key in "filename".

     -signature filename
	 The actual signature to verify.

     -hmac key
	 Create a hashed MAC using "key".

	 Cannot be used together with -mac option.  If multiple -hmac, -hmac-env
	 or -hmac-stdin options are specified, the last one is applied.

	 The openssl-mac(1) command should be preferred to using this command
	 line option.

     -hmac-env var
	 Create a hashed MAC using a key from the environment variable "var".

	 Cannot be used together with -mac option.  If multiple -hmac, -hmac-env
	 or -hmac-stdin options are specified, the last one is applied.

	 The openssl-mac(1) command should be preferred to using this command
	 line option.

     -hmac-stdin
	 Create a hashed MAC using a key obtained from the standard input. Only
	 the first line from stdin is read, and the \0 character also terminates
	 the key.

	 Cannot be used together with -mac option.  If multiple -hmac, -hmac-env
	 or -hmac-stdin options are specified, the last one is applied.

	 The openssl-mac(1) command should be preferred to using this command
	 line option.

     -mac alg
	 Create MAC (keyed Message Authentication Code). The most popular MAC
	 algorithm is HMAC (hash-based MAC), but there are other MAC algorithms
	 which are not based on a digest algorithm, for instance the gost-mac
	 algorithm, supported by the gostprov provider. MAC keys and other op-
	 tions should be set via -macopt parameter.

	 Cannot be used together with -hmac, -hmac-env and -hmac-stdin.

	 The openssl-mac(1) command should be preferred to using this command
	 line option.

     -macopt nm:v
	 Passes options to MAC algorithm, specified by -mac key.  Following op-
	 tions are supported by both by HMAC and gost-mac:

	 key:string
	     Specifies MAC key as alphanumeric string (use if key contain print-
	     able characters only). String length must conform to any restric-
	     tions of the MAC algorithm for example exactly 32 chars for
	     gost-mac.

	 hexkey:string
	     Specifies MAC key in hexadecimal form (two hex digits per byte).
	     Key length must conform to any restrictions of the MAC algorithm
	     for example exactly 32 chars for gost-mac.

	 keyenv:var
	     Read the MAC key as an alphanumeric string from the environment
	     variable (use if the key contains printable characters only).  The
	     the key length must conform to any restrictions of the MAC algo-
	     rithm.  A key must be specified for every MAC algorithm.

	 keyenvhex:var
	     Read the MAC key in hexadecimal form (two hex digits per byte) from
	     the environment variable.	The key length must conform to any re-
	     strictions of the MAC algorithm.  A key must be specified for every
	     MAC algorithm.

	 keyfile:filename
	     Read the MAC key from the specified file. The key is read as binary
	     data.  The key length must conform to any restrictions of the MAC
	     algorithm.  A key must be specified for every MAC algorithm.

	 keystdin
	     Read the MAC key from the standard input. Only the first line from
	     stdin is read, and the \0 character also terminates the key.  The
	     key length must conform to any restrictions of the MAC algorithm.
	     A key must be specified for every MAC algorithm.

	 If multiple MAC key options are specified, the last one is applied.

	 The openssl-mac(1) command should be preferred to using this command
	 line option.

     -fips-fingerprint
	 Compute HMAC using a specific key for certain OpenSSL-FIPS operations.

     -rand files, -writerand file
	 See "Random State Options" in openssl(1) for details.

     -provider name
     -provider-path path
     -provparam [name:]key=value
     -propquery propq
	 See "Provider Options" in openssl(1), provider(7), and property(7).

     file ...
	 File or files to digest. If no files are specified then standard input
	 is used.

EXAMPLES
     To create a hex-encoded message digest of a file:

      openssl dgst -md5 -hex file.txt
      or
      openssl md5 file.txt

     To sign a file using SHA-256 with binary file output:

      openssl dgst -sha256 -sign privatekey.pem -out signature.sign file.txt
      or
      openssl sha256 -sign privatekey.pem -out signature.sign file.txt

     To verify a signature:

      openssl dgst -sha256 -verify publickey.pem \
      -signature signature.sign \
      file.txt

NOTES
     The digest mechanisms that are available will depend on the options used
     when building OpenSSL.  The "openssl list -digest-algorithms" command can
     be used to list them.

     New or agile applications should use probably use SHA-256. Other digests,
     particularly SHA-1 and MD5, are still widely used for interoperating with
     existing formats and protocols.

     When signing a file, this command will automatically determine the algo-
     rithm (RSA, ECC, etc) to use for signing based on the private key's ASN.1
     info.  When verifying signatures, it only handles the RSA, DSA, or ECDSA
     signature itself, not the related data to identify the signer and algorithm
     used in formats such as x.509, CMS, and S/MIME.

     A source of random numbers is required for certain signing algorithms, in
     particular ECDSA and DSA.

     The signing and verify options should only be used if a single file is be-
     ing signed or verified.

     Hex signatures cannot be verified using openssl.  Instead, use "xxd -r" or
     similar program to transform the hex signature into a binary signature
     prior to verification.

     The openssl-mac(1) command is preferred over the -hmac, -mac and -macopt
     command line options.

SEE ALSO
     openssl-mac(1)

HISTORY
     The default digest was changed from MD5 to SHA256 in OpenSSL 1.1.0.  The
     FIPS-related options were removed in OpenSSL 1.1.0.

     The -engine and -engine_impl options were removed in OpenSSL 4.0.

     The -hmac-env and -hmac-stdin options were added in OpenSSL 4.0.

COPYRIGHT
     Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved.

     Licensed under the Apache License 2.0 (the "License").  You may not use
     this file except in compliance with the License.  You can obtain a copy in
     the file LICENSE in the source distribution or at
     <https://www.openssl.org/source/license.html>.

4.0.2				   2026-08-25		     OPENSSL-DGST(1ossl)

Want to link to this manual page? Use this URL:
<https://man.freebsd.org/cgi/man.cgi?query=openssl-dgst&sektion=1&manpath=FreeBSD+Ports+15.1.quarterly>

home | help