Skip to content

doc: crypto.sign and crypto.verify string/buffer keys must be pem #35331

Description

@jacobleesinger

📗 API Reference Docs Problem

  • Version: v12.16.2
  • Platform: Darwin Jacobs-MacBook-Pro.local 18.6.0 Darwin Kernel Version 18.6.0: Thu Apr 25 23:16:27 PDT 2019; root:xnu-4903.261.4~2/RELEASE_X86_64 x86_64
  • Subsystem: crypto

Location

Section of the site where the content exists

Affected URL(s):

Description

Concise explanation of the problem

According to the documentation for crypto.sign and crypto.verify, the key argument may be a string, buffer, object, or KeyObject. It does not mention that if the key is a string or buffer, it must be pem format. Passing a key with der format will result in an error error:0909006C:PEM routines:get_name:no start line

The source code is quite clear that keys are assumed to be pem.

} else if (typeof key === 'string' || isArrayBufferView(key)) {
// Expect PEM by default, mostly for backward compatibility.
return { format: kKeyFormatPEM, data: key };
} else if (typeof key === 'object') {


  • I would like to work on this issue and
    submit a pull request.

Activity

  1. added
    docIssues and PRs related to Node.js documentation.
    on Sep 24, 2020
  2. added
    cryptoIssues and PRs related to the crypto subsystem.
    on Oct 26, 2020
  3. panva commented on Nov 30, 2020

    @panva
    Member

    The docs do note

    If key is not a KeyObject, this function behaves as if key had been passed to crypto.createPrivateKey().

    If key is not a KeyObject, this function behaves as if key had been passed to crypto.createPublicKey().

    Then the create*Key methods do say that

    If key is a string or Buffer, format is assumed to be 'pem'

    Personally i think this is clear and removes a lot of documentation duplication that would have to be in place if this was to be mentioned all repeated in crypto.sign, crypto.verify, Sign.prototype.sign, and Verify.prototype.verify

  4. Trott commented on Dec 2, 2020

    @Trott
    Member

    I agree with the avoiding-duplication point. Still, if this is tripping up users, then I also wouldn't mind mentioning PEM. Maybe something like this?

    If key is not a KeyObject, this function behaves as if key had been passed to crypto.createPublicKey(). For example, strings and buffers must be in PEM format.

  5. github-actions commented on Jun 27, 2026

    @github-actions
    Contributor

    This issue has been marked as stale due to 210 days of inactivity.
    It will be automatically closed in 30 days if no further activity occurs. If this is still relevant, please leave a comment or update it to keep it open.

  6. added
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Jun 27, 2026
  7. added a commit that references this issue on Aug 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cryptoIssues and PRs related to the crypto subsystem.docIssues and PRs related to Node.js documentation.staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions