SAMPLE RSA Private Key: PKCS#8, Encrypted
The SAMPLE leaf key under PKCS#8 password encryption (BEGIN ENCRYPTED PRIVATE KEY, PBES2), password `novus-p7-sample-pkcs8`. Encryption metadata lives inside the ASN.1 here, not in PEM headers: the opposite of the PKCS#1 twin.
-----BEGIN ENCRYPTED PRIVATE KEY-----
MIIFNTBfBgkqhkiG9w0BBQ0wUjAxBgkqhkiG9w0BBQwwJAQQb8sWm/ysdEjQcZ+x
VTIJFwICCAAwDAYIKoZIhvcNAgkFADAdBglghkgBZQMEASoEEKCWzndYKIpBU2XY
5QaAKisEggTQ+BWYvAttJE3iPIgCysNF4TnKkNpAchDvQAX+K2i8+XyRPiURdwRf
M8tlaqvRz9ikGFv4lYh51J9LAvJFCE42xRf+VJDGgRlVXGP4druBg0cJMpZpl4Hq
W4E9fP0g8XiIM5Vtm4CTGPYBjg2pituk1+ExuOMxzTt3fxm0wY3DbHFXpM/EZbWm
KnJIWCJN7guBt64r0ljKqaxRpoSefx/3KzHEVyj/OrOkJkGBB6W7DcHwKGtho0fK
pE7q+lIFlIyebd7gZC9NXWbPDex+X9I/Wbko3xwlwFljowtKbeUzzrK+uGH5YQZp
quGLeNobNlYzwTGEBfctVgg6OCsM3RsSEw00CqpJjEcXPdFDC9JeMoQ09rSX6QlA
DS4Mb6mURHdNoey5HCeQR86khR7tvQrswVcCCwLJbe4srioPT6gpKvWeQnQsmA1i
TZy8/yeJDOmdpHdi0kfpfqzdzGZYuyPMy5B6v94e3ab8Sk49DHLQeSWKSPt1i56C
IvqjKWfCtAAT3GEJHPXvBveFBIWD+VIbWGl3RG6OunHnEjHSGXF7JeJAhIgJ7ZYs
RcnUUcRc85Pf8+MDB0j34qFrwj8LRv4TzsbQ644UD+v1tsQOH08op+SVLVp6cbfq
vf4sSgzkBUXuCJMZ2iGMy/ChweDWdkQLonqqvtecJOGi3giuTFGpknkfb8oQNKgZ
Bv03ivsXAVQ7EKhnwY1CRw4syUUfmxZbZWMJTWZcVL4qDSKmCayUQLGJNdX5HIqm
gxB3cpfn7rjvLZ8p2u5ItaVivfaPA9RP9zftbJNad7gi+MK/YK9IfNH/qS/xq9p+
sv/Egbukyq9GgxBg88A3y7qNPt5HimtfnBw2HL4MYfdmrVI3OdzwXzTa4QSyS549
QfT/kPN7VQwabnLuSMIewQv7YhNlpDgJ6lnnir+VcHc3RXkv6FWnudULucTYauFZ
KKPdMrmZ2CVdGc/LOBkB+haD0kYE+VxYlmjs0ddz1uFHeJi62Ko4YtqIs23Zjbne
D+rjCM1ZgvEk/4u1R3p8cgg7LHt2EeDBesmKiIsV/2hk2YccFL16G45sTXqnX37x
J5b+9XHN0pl0UgSc1030g1v4XYKIbNGGDx6Epn9zO119ot8lFsOq+CwEVR8kC9do
CzctCYQgsu4SxZV92qu/dh2V56AeUNrPO6B38qDwsD5FeeYnX7n0ZuMq5J5v7dwG
22zRaW18AMkqwdnPhRoWhiEGhcBIXxYPU4koDGeMcRKx8lfUATo99dVXvCDq+SQE
e6L3+4VawL9ol0ResYkWKKDOvB0I40WyLqaQZJ76EhYWRQA/vXtAi6Xd3tOpgHbQ
XW6SC0kmP8yoYbyfh8Kq9H9ma3RmrzvOhgg5IwF9HKmNo9VS/B7Y6ItldwGEpig2
K0RSqVJLihU+3Eh3pRscgyoreDTdhB6mRRDhdfFgEtAsyn/OWZDaOi5Dd/37R8Y3
nYw59Ny0x0NA4DL4POj9xWWTZ3yPE2KE/3husHW5fHbB8KUERLG1NHJpgpnoLjoq
jQG54Bq64pO9jcsXMXGgeDgRxbmCixjgRqL1fwO+8UMyMb27+VUCXgFC702FDP8H
a29jeZPTojowVZsu9MdTj7kQn+2lZyTdCmcF8Db3VrpOUH1uANEUKkE=
-----END ENCRYPTED PRIVATE KEY-----
Specifications
- Algorithm
- RSA
- Bits
- 2048
- Container
- PKCS#8 encrypted (PBES2)
- Armour
- BEGIN ENCRYPTED PRIVATE KEY
- Password
- novus-p7-sample-pkcs8
- Encrypted
- true
- Pinned
- PBES2 salt and IV are per-run random, so these bytes are pinned in the generator
- Sample Only
- true
- Seed
- 70117
Testing contract
Expected to pass- Scenario
- Load the key with password `novus-p7-sample-pkcs8` and again with a wrong password.
- Expected result
- The correct password yields the same RSA key as the plain PKCS#8 file; the wrong one raises a decryption error rather than returning garbage.
What is a .key file?
A .key file holds a private key, usually PEM-encoded in PKCS#8 (BEGIN PRIVATE KEY) or a key-type-specific format. It is the secret half of a TLS or SSH identity and must normally be protected. The examples here are published, sample-only keys that must never be used in production.
How to use this file
Use an example .key to test PEM key parsers, PKCS#8 decoders, and key-format converters (for example PEM to DER or OpenSSH). These are deliberately published sample keys, for parser testing only, never for real use.
How to use this file for testing
“SAMPLE RSA Private Key: PKCS#8, Encrypted” is a deterministic Testaroo fixture for Certificate & key testing. Self-signed X.509 certificates (PEM, CRT, DER), a CSR, RSA and Ed25519 keys, an SSH public key, a PKCS#12 bundle, and an htpasswd file, all published sample-only material, for testing certificate parsers, TLS tooling, keystore importers, and PEM/DER decoders.
Documented properties for this file: seed 70117 · RSA. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such, expect parsers to fail loudly rather than silently accept them.
This is published, SAMPLE-only security material, never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.
This is a published, sample-only certificate/key. Parse it, verify the chain or signature, and test PEM↔DER conversion, never deploy it anywhere real.
Generated by generation/security_p7.py. Free for any use, no attribution required, license.
Related files
- jsonCRL Metadata JSON: SAMPLESAMPLE CRL metadata JSON (no binary CRL) for revocation-list UI and loader tests.

- keyEd25519 Private Key (PEM): SAMPLEDeterministic SAMPLE Ed25519 private key for SSH/TLS tooling tests.

- keyEncrypted PKCS#8 RSA Key: SAMPLEPassword-encrypted SAMPLE PKCS#8 private key (password printed in specs) for decrypt-import tests.

- csrPKCS#10 CSR: Security SAMPLEPKCS#10 certificate signing request SAMPLE for CSR parsers and CA tooling smoke tests.

- p12PKCS#12 Bundle (.p12): SAMPLESAMPLE PKCS#12 keystore (password `novus-sample-wg`) for keystore importer tests. Not byte-stable.

- keyRSA-2048 Private Key (PEM): SAMPLEPublished SAMPLE RSA-2048 private key (PKCS#8 PEM). Never use for a real identity.
