Lukis' Space

← Tools

SSH key fingerprint

SHA256 and MD5 fingerprints, key type and size, and SSHFP records for a public key. Private keys are refused unread.

Runs entirely in your browser. Nothing you enter here is sent to the server.

One key per line: a .pub file, or lines from authorized_keys or known_hosts. Options, host names and markers in front of the key are fine; lines starting with # are skipped. Private keys are refused unread.

Comparing fingerprints, SSHFP, and why private keys are refused

A fingerprint is a hash of the public key, so two people can check they mean the same key by reading out a short string instead of the whole thing. The key is decoded and hashed in this page; nothing is sent anywhere and nothing is stored.

SHA256
What OpenSSH has shown since 6.8: in the "authenticity of host can't be established" prompt, in ssh-keygen -lf, and in the SSH key lists of Gitea and GitHub. Base64 of the SHA-256 of the key, without the = padding.
MD5
The older colon-separated form, still shown by some old servers and panels. ssh-keygen -E md5 -lf prints it. Fine for recognising a key; compare the SHA256 one when you can.
Size
RSA is the modulus length; under 2048 bits is weak. ECDSA is the curve. Ed25519 is always 256. DSA is flagged because OpenSSH 10 dropped it.
sk- types
Keys held on a FIDO security key. The application string is usually ssh:.

Check the whole string

Matching the first and last few characters is weaker than it looks: a key whose fingerprint starts and ends with the same few characters can be found by brute force. Compare all of it.

SSHFP records

Published in DNS, they let ssh -o VerifyHostKeyDNS=yes check a server's host key without asking you. Type 1 is SHA-1 and type 2 is SHA-256; publishing type 2 alone is enough today. Run ssh-keygen -r host on the server to get the same records for all of its host keys at once. Without DNSSEC on the zone, ssh treats a match as a hint and still asks.

Private keys

Anything containing PRIVATE KEY is refused before it is read. The fingerprint comes from the public half, so there is never a reason to paste the private one; if a site asks for it, that site is the problem. ssh-keygen -y -f ~/.ssh/id_ed25519 prints the public key from a private one.

A hashed known_hosts entry (|1|…) cannot be turned back into a host name; ssh-keygen -F host tells you whether it is that host.

Other tools

  • Code scanner — Read QR codes and barcodes with your camera or from an image. Every format ZXing knows.
  • Code generator — Make a QR code, Data Matrix, Aztec, PDF417 or a linear barcode and download it.
  • Link inspector — See where a link really goes before you open or shorten it: the real host, lookalike letters, hidden redirects and tracking parameters.
  • Base converter — Encode and decode between text and Base2 through Base85, or convert integers between any two bases.
  • Hash generator — MD5, SHA family, CRC32 and MySQL5 over text or a file. The file is read in your browser.
  • JWT decoder — Read a JSON Web Token's header and claims, with every timestamp as a date. Decoded right here; the token is never sent or stored.
  • Password generator — Random passwords from a CSPRNG, with the character classes you pick.
  • TOTP generator — Turn a TOTP secret or otpauth:// link into the current code. The secret stays on your device.
  • Timestamp converter — Unix time to a calendar date and back, in every format at once. Live clock included.
  • Subnet calculator — IPv4 and IPv6: network, range, host count, masks and reverse-DNS pointers.
  • Image resizer — Resize and convert an image without it ever leaving your browser. Re-encoding drops EXIF and GPS.
  • IP info — Your public IPv4 and IPv6, as this server sees them.
  • PHP obfuscator — Wrap PHP so it self-decodes at runtime. Runs on the server; the code is never stored.