Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

RSA/ECB/OAEPWithSHA-256AndMGF1Padding is a Java Cryptography Architecture transformation for RSA encryption using OAEP. For reliable interoperability, do not rely on the name alone: explicitly set the OAEP digest to SHA-256, MGF1’s digest to SHA-256, and the label to empty. Use the recipient’s public key to encrypt and matching private key to decrypt. RSA-OAEP is for small secrets such as AES keys, not bulk files or large messages.

What each part of the name means

  • RSA: the asymmetric public-key algorithm. The recipient’s public key encrypts; the matching private key decrypts.
  • ECB: a legacy or syntactic component of Java’s familiar algorithm/mode/padding naming form. RSA-OAEP is not using an AES-style Electronic Codebook mode: RSA is not a block cipher that encrypts independent ECB blocks.
  • OAEP: Optimal Asymmetric Encryption Padding, the encoding used by the standardized RSAES-OAEP scheme.
  • WithSHA-256: SHA-256 is the primary OAEP hash.
  • AndMGF1: OAEP uses MGF1, a mask-generation function. Its digest is a separate parameter that must be confirmed.
  • Padding: conventional naming; OAEP is a randomized structured encoding, not merely a few fixed padding bytes.

The transformation is for encryption, not signatures. RSA signatures use the Signature API with a signature scheme such as RSASSA-PSS. OAEP and PSS serve different purposes even though both may involve MGF1. The PKCS #1 v2.2 specification (RFC 8017) defines RSAES-OAEP and recommends OAEP for new applications; PKCS#1 v1.5 encryption remains relevant chiefly for compatibility.

Set every OAEP parameter explicitly

The transformation string is not a complete, portable description of every parameter. In particular, implementations can differ on whether MGF1 uses SHA-1 or SHA-256 when the primary OAEP hash is SHA-256. Those parameter sets cannot decrypt one another’s ciphertext. Specify the parameters in Java and agree on the same tuple with every other implementation: OAEP digest, MGF algorithm, MGF1 digest, and label.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
import javax.crypto.Cipher;
import javax.crypto.spec.OAEPParameterSpec;
import javax.crypto.spec.PSource;
import java.security.spec.MGF1ParameterSpec;

private static final OAEPParameterSpec OAEP_SHA256 =
    new OAEPParameterSpec(
        "SHA-256",
        "MGF1",
        MGF1ParameterSpec.SHA256,
        PSource.PSpecified.DEFAULT
    );

static byte[] encrypt(byte[] plaintext, PublicKey publicKey) throws Exception {
    Cipher cipher = Cipher.getInstance(
        "RSA/ECB/OAEPWithSHA-256AndMGF1Padding");
    cipher.init(Cipher.ENCRYPT_MODE, publicKey, OAEP_SHA256);
    return cipher.doFinal(plaintext);
}

static byte[] decrypt(byte[] ciphertext, PrivateKey privateKey) throws Exception {
    Cipher cipher = Cipher.getInstance(
        "RSA/ECB/OAEPWithSHA-256AndMGF1Padding");
    cipher.init(Cipher.DECRYPT_MODE, privateKey, OAEP_SHA256);
    return cipher.doFinal(ciphertext);
}

This sets SHA-256 for both OAEP and MGF1 and uses the empty label. Java’s OAEPParameterSpec.DEFAULT historically means SHA-1 for both digests and an empty label; Oracle has deprecated that default for new use. Construct the desired parameters explicitly instead. See the OAEPParameterSpec documentation and MGF1ParameterSpec documentation.

For compatibility, verify what the other side actually specifies rather than inferring it from a similar algorithm name. For example, AWS documents its RSAES-OAEP-SHA-256 algorithm as using SHA-256 for both hashes; Google’s Java example also supplies SHA-256 explicitly for MGF1. See AWS KMS RSA key specifications and Google Cloud KMS RSA encryption and decryption.

What OAEP does—and does not do

OAEP encodes a message with a random seed before the RSA operation. At a high level, it incorporates the hash of a label, the message and padding structure, and masks derived using MGF1. Because the seed is random, encrypting the same bytes twice with the same key should ordinarily produce different ciphertexts. Tests should not expect a fixed ciphertext unless randomness is deliberately controlled in a test-only environment.

The label is optional input to OAEP. The conventional default is the empty label, represented in Java by PSource.PSpecified.DEFAULT. Encryption and decryption must use the same label; use a non-empty one only when the protocol explicitly requires it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OAEP is encryption, not proof of who sent the message: anyone with the public key can encrypt. Successful OAEP decoding is not a digital signature or a substitute for sender authentication, authorization, replay protection, or an authenticated surrounding protocol. Avoid exposing detailed decryption failures to remote callers; distinguishable errors or timing can create a useful oracle for attackers. RFC 8017 discusses the scheme and implementation considerations.

Plaintext limits: count bytes, not characters

RFC 8017 gives the RSAES-OAEP maximum message length as mLen ≤ k − 2hLen − 2, where k is the RSA modulus size in bytes and hLen is the hash output size. With SHA-256, hLen is 32, so the maximum is modulusBytes − 66.

RSA key size Modulus bytes Maximum plaintext with SHA-256 OAEP
1024 bits 128 62 bytes
2048 bits 256 190 bytes
3072 bits 384 318 bytes
4096 bits 512 446 bytes

The limit applies to the byte array passed to doFinal, not the character count. UTF-8 characters can occupy multiple bytes. For text, convert explicitly with StandardCharsets.UTF_8 and check the resulting array length. Base64 is only a text representation for transporting binary ciphertext; its expanded length does not change the RSA plaintext limit. A 2048-bit RSA ciphertext is 256 bytes before Base64 encoding.

Use RSA-OAEP to wrap a key, not encrypt a file

For a document, file, or larger payload, use hybrid encryption. Generate a random symmetric key, encrypt the data with an authenticated cipher such as AES-GCM, and encrypt (wrap) the small symmetric key with RSA-OAEP. The envelope carries the wrapped key, nonce, ciphertext, authentication tag, and any required metadata. This avoids RSA’s strict size limit and is generally more efficient. Do not invent a scheme that splits a long message into independent RSA operations; custom chunking creates framing, ordering, replay, and authenticity hazards.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

RSA-2048, RSA-3072, and RSA-4096 have different performance, compatibility, and policy trade-offs. A larger key raises the OAEP message limit but does not make RSA appropriate for bulk encryption. Follow the applicable security policy, provider constraints, and protocol requirements rather than treating one size as universally right.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keys, text, and transport

Keep the private key protected; distribute only the public key to encryptors. PEM is a text wrapper around encoded key bytes, not itself the key format. Public keys commonly use X.509 SubjectPublicKeyInfo encoding and private keys commonly use PKCS#8. To import an X.509 public key from DER:

X509EncodedKeySpec keySpec = new X509EncodedKeySpec(derBytes);
PublicKey publicKey = KeyFactory.getInstance("RSA").generatePublic(keySpec);

If the input is PEM, remove the header and footer and Base64-decode its contents before creating the key specification. When transporting ciphertext in text, Base64-encode the ciphertext bytes and decode them back to bytes before decryption. Never convert arbitrary ciphertext directly to a text string.

Troubleshooting interoperability and errors

  • BadPaddingException on decryption: commonly indicates OAEP decoding failed—not necessarily literal damaged padding. Check the private key, OAEP hash, MGF1 hash, label, ciphertext integrity, Base64 handling, and whether one side used PKCS#1 v1.5 instead of OAEP.
  • “Message too long,” IllegalBlockSizeException: compare the input byte length with k − 2hLen − 2. For RSA-2048/SHA-256 OAEP it is 190 bytes. Use hybrid encryption rather than several RSA calls.
  • InvalidKeyException or initialization failure: check that the key is RSA and of a supported size, that its encoding is valid, and that the configured provider or FIPS policy permits the algorithm. A public X.509 key commonly reports algorithm RSA and format X.509.
  • Local decryption works but another language or KMS fails: compare the full parameter tuple—key, OAEP digest, MGF algorithm, MGF1 digest, label—and the exact ciphertext bytes. Do not compare only transformation names.

Java documents the transformation among standard names, but providers and security policies can affect availability and behavior. Test on the actual JDK, provider, and deployment configuration, including FIPS mode if applicable. The Java standard names specification lists the transformation for implementations supporting the stated RSA key sizes; it does not remove the need to validate your target runtime.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Checklist before shipping

  • Set SHA-256, MGF1, MGF1-SHA-256, and the protocol’s exact label explicitly.
  • Use the public key to encrypt and the matching private key to decrypt; protect the private key.
  • Measure plaintext in bytes and respect the OAEP limit.
  • Use a standard hybrid-encryption or envelope format for data beyond a small secret.
  • Document the full OAEP parameter tuple for every interoperability boundary.
  • Return uniform external decryption errors and protect detailed diagnostics.
  • Test both directions across the actual providers and services you will deploy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.