Skip to main content
Version: 1.28 (Current)

Generate RSA Keys

Audience: Low-code Engineers

Skill Prerequisites: Actions, Tokens

Creates a new random RSA key pair and saves it in tokens. You get the public key and the private key, each in two versions: a single-line base64 string and a PEM block with -----BEGIN ... KEY----- headers.

PEM is the standard key format most tools read, such as OpenSSL, Node.js, Java and DKIM records in DNS.

note

This action is part of the Security add-on (DnnSharp.Security). The add-on also provides Verify DKIM DNS Record. If you don't see these two actions in the Security group, the add-on isn't installed. The action doesn't check a license feature.

Typical Use Cases​

  • Create a DKIM key pair: publish the public key in DNS, then check it with Verify DKIM DNS Record
  • Create a key pair for each customer or tenant in a setup workflow
  • Create a key pair to give a partner system that expects PEM keys

Don't use it to​

  • Create keys for RSA Encrypt and RSA Decrypt. Those actions need XML keys, and this action creates PEM keys. Use the key generator linked in their Public Key and Private Key help texts instead.
  • Create an AES key. Use the key generator linked in the AES Key help text of AES Encrypt.
Action NameDescription
Verify DKIM DNS RecordChecks a domain's DKIM record against a public key. It accepts the PublicKey token of this action.
RSA EncryptEncrypts values with a public key in XML format.
RSA DecryptDecrypts values with a private key in XML format.
Add ConnectorSaves values, such as a private key, encrypted in a connector.

Input Parameter Reference​

ParameterDescriptionSupports TokensDefaultRequired
Key LengthThe key size in bits: 512, 1024, 2048 or 4096. Pick 2048 or more. Values below 512 are raised to 512.No1024No
Output TokenThe prefix for the output tokens, for example DkimKey. If it's empty, the action does nothing.Noempty stringYes

Output Parameters Reference​

TokenDescription
[<Output Token>:PublicKey]The public key as one base64 line, without headers. This is the X.509 SubjectPublicKeyInfo format, the same value you put in the p= tag of a DKIM record.
[<Output Token>:PublicKeyPem]The same public key as a PEM block between -----BEGIN PUBLIC KEY----- and -----END PUBLIC KEY-----, with 64 characters per line.
[<Output Token>:PrivateKey]The private key as one base64 line, without headers. This is the unencrypted PKCS#8 format.
[<Output Token>:PrivateKeyPem]The same private key as a PEM block between -----BEGIN PRIVATE KEY----- and -----END PRIVATE KEY-----, with 64 characters per line.

The PEM blocks use line feeds (\n) as line breaks.

Considerations​

  • Change the default key length. The default is 1024 bits, and 512 is also offered. Both are too weak for new keys today. Use 2048, or 4096 for long-lived keys. Many DNS providers limit TXT record length, so 2048 is the usual choice for DKIM.
  • The private key isn't password protected. Anyone who gets the PrivateKey token value can use the key. Save it right away somewhere protected, for example with Add Connector, which stores values encrypted. Don't log it, email it or send it to the browser.
  • Each run creates a new pair. Keys aren't saved anywhere by the action. If you run it again, you get different keys, and anything tied to the old public key stops working.
  • Not for RSA Encrypt or RSA Decrypt. Those actions only accept XML keys. See Don't use it to.
  • Large keys are slow. A 4096-bit key can take a noticeable moment to generate.

Examples​

tip

To understand how to use the below examples, please see Running Examples.

1. Create a DKIM key pair​

This action creates a 2048-bit key pair. [DkimKey:PublicKey] goes in the DKIM TXT record as p=[DkimKey:PublicKey]. [DkimKey:PrivateKeyPem] goes to the mail server.

{
"Title": "Generate RSA Keys",
"ActionType": "GenerateRsaKey",
"Description": "Create a DKIM key pair",
"Parameters": {
"KeyLength": "2048",
"OutputToken": "DkimKey"
}
}

Revised 09/27/2026