11

When the certificate is created it is possible to configure -keysize option for command genkeypair.

Is it possible to see a certificate keysize using keytool?

I have tried these options without success:

keytool  -list –rfc

keytool  -list –v

Was not able to find it here: https://docs.oracle.com/javase/8/docs/technotes/tools/unix/keytool.html#keytool_option_list

Michael
  • 10,063
  • 18
  • 65
  • 104

2 Answers2

11

This is not possible with keytool, but there is a GUI alternative called "KeyStore Explorer" that shows the key size:

KeyStore Explorer

Omikron
  • 4,072
  • 1
  • 27
  • 28
2

Actually, if I run the following command I will see the bit size listed under my Alias

keytool -list -v -keystore {name of keystore}

The following are lines I see on my private certificate (non-root cert)

Subject Public Key Algorithm: 2048-bit RSA key

DanielM
  • 3,598
  • 5
  • 37
  • 53