# jsrsasign: a pure JavaScript PKI toolkit that reaches end of support on 14 Aug 2026

> jsrsasign covers signing, X.509, CMS, OCSP and JWT without OpenSSL or the Web Crypto API. The README declares end of support on 14 Aug 2026 and the npm packages are deprecated, so the decision is no longer whether to adopt it but how long you can keep it.

**kjur/jsrsasign** — CAUTION: END OF SUPPORT ON 14 AUG 2026. The 'jsrsasign' (RSA-Sign JavaScript Library) is an opensource free cryptography library supporting RSA/RSAPSS/ECDSA/DSA signing/validation, ASN.1, PKCS#1/5/8 private/public key, X.509 certificate, CRL, OCSP, CMS SignedData, TimeStamp, CAdES and JSON Web Signature/Token in pure JavaScript.

- Repository: https://github.com/kjur/jsrsasign
- Website: https://kjur.github.io/jsrsasign
- Stars: 3,369 · Forks: 650
- Language: HTML
- License: NOASSERTION
- Published: 2026-09-24 · Updated: 2026-09-24 · Language: en
- Canonical page: https://hysenlabs.com/projects/kjur-jsrsasign

## The problem jsrsasign solves, and the deadline attached to it

Most JavaScript crypto stops at key generation, hashing and a signature. jsrsasign goes further into the formats that surround them: ASN.1 encoding, PKCS#1, PKCS#5 and PKCS#8 keys, X.509 certificates, CRLs, OCSP requests, CMS SignedData, TimeStamp and CAdES. The README describes it as a "Swiss Army Knife style all in one package crypto and PKI library" and states that it depends on neither the W3C Web Cryptography API nor OpenSSL. That combination is why it still appears in Node scripts that parse a certificate or verify a detached CMS signature without shelling out to openssl.

The deadline is the part that changes the buying decision. The README carries an End of Support Announcement: effective 14 Aug 2026, support is no longer provided and all versions of the npm package are deprecated. The final release, 11.1.4 on 2026-08-14, is labelled both "final release" and "END OF SUPPORT" in the news list. The repository is not archived and the last push was on 2026-08-19, so the code is still reachable, but the project's own documentation says the maintenance relationship is over. Anyone evaluating jsrsasign today is really evaluating a frozen dependency.

## How the library is put together: modules, ASN.1 and the ext directory

The Makefile exposes the architecture more clearly than the README does. The minified build is assembled from named modules: asn1-1.0, asn1hex-1.1, asn1x509-1.0, asn1cms-1.0, asn1tsp-1.0, asn1cades-1.0, asn1csr-1.0, asn1ocsp-1.0, base64x-1.1, crypto-1.1, ecdsa-modified-1.0, ecparam-1.0, dsa-2.0, keyutil-1.0, rsapem-1.1, rsasign-1.2, x509-1.1, jws-3.3, jwsjs-2.0, x509crl and nodeutil-1.0. Each ASN.1 module maps to one PKI structure, which is why the API surface is broad but shallow: you get a class per format rather than a single general parser.

Below that sits the ext directory, built from base64, jsbn, jsbn2, prng4, rng, rsa, rsa2, ec, ec-patch and json-sans-eval. The big integer arithmetic and the RSA and elliptic curve primitives live there rather than in the top-level modules. The README notes that version 11.0.0 split the package into modules that had all been bundled together before 11.0.0, and the 11.0.0 notice says a module bundler such as browserify or webpack would be used and that the unit test framework moved from QUnit and mocha to jest. The repository layout matches that: src/ for sources, min/ for the minified modules listed in the Makefile, npm/ and npm_util/ for the two published packages, api/ for generated documentation, and sample/ plus sample_node/ for runnable examples.

One consequence of the module split is worth stating plainly. If you load individual min/ files instead of the all-in-one bundle, you are responsible for the load order, because jws-3.3 depends on rsasign-1.2 and x509-1.1, which in turn depend on the ASN.1 and base64 modules. The Makefile encodes that order; the README does not.

## Installing jsrsasign and signing a string with a PKCS#5 key

The README gives two install paths. For Node, the command installs the main package and the companion utility package that provides file reading:

```bash
npm install jsrsasign jsrsasign-util
```

The second path is a browser script tag pointing at a CDN. The README's example pins version 8.0.20, which is not the latest release, so treat it as a shape rather than a recommendation:

```bash
<script src="https://cdnjs.cloudflare.com/ajax/libs/jsrsasign/8.0.20/jsrsasign-all-min.js"></script>
```

A bower install also appears in the README, but the 11.0.0 notice states that bower support was dropped, so that instruction is stale for current versions.

The README's usage example loads an encrypted PKCS#5 private key from a PEM file and signs the string 'aaa'. The key loader takes the PEM text and the passphrase together:

```js
var rs = require('jsrsasign');
var rsu = require('jsrsasign-util');
var pem = rsu.readFile('z1.prv.p5e.pem');
var prvKey = rs.KEYUTIL.getKey(pem, 'passwd');
```

Signing is then a four-step sequence: construct a Signature with an algorithm name, initialise it with the key, feed it the data, and call sign(). The README shows SHA1withRSA and prints a truncated signature value:

```js
var sig = new rs.Signature({alg: 'SHA1withRSA'});
sig.init(prvKey);
sig.updateString('aaa');
var sigVal = sig.sign();
```

The README's own output line is 'd764dcacb...'. Two things to check before copying this: the README writes the first line as "var sig = new a.Signature" in one place, which looks like a typo for the required namespace, and SHA1withRSA is a weak choice for anything new. The algorithm string is the only thing that selects the digest, so it is worth reading the Signature class documentation rather than reusing the sample verbatim.

## Where jsrsasign fails you: RSA decryption, weak defaults and a frozen advisory list

The sharpest limitation is not stylistic. The README's 2024-Jan-16 news entry records a security advisory for the Marvin attack, CVE-2024-21484 with CVSS 7.5, and states that because of it, RSA PKCS#1.5 and RSA-OAEP encryption and decryption are no longer supported from 11.0.0 onward. Code that decrypts a PKCS#1.5 ciphertext with jsrsasign does not merely become discouraged; the functionality was removed. If your system exchanges encrypted RSA payloads in those padding modes through this library, jsrsasign is the wrong tool and no configuration flag brings it back.

The advisory table lists two earlier entries: CVE-2022-25898, a JWS and JWT signature validation vulnerability with special characters, fixed in 10.5.25, and a 2021 RSA signature validation vulnerability on malleable encoded messages, fixed in 10.2.0. The table is worth reading as a version floor rather than as history. Any deployment below 11.1.4 is missing the final round of fixes, and the README does not document a backport policy, because there is no longer a project to backport.

There is a second failure mode that has nothing to do with vulnerabilities. Because the library avoids newer ECMAScript features for backward compatibility, its own style is old. The 11.0.0 notice says modern functions such as Promise, let, array methods and class would be introduced, and that Internet Explorer support would stop, so the modernisation is partial and recent. If your build assumes tree-shakeable ES modules, the min/ files and the all-in-one bundle are not that. The README does not document a rollback procedure for a bad upgrade, and it does not describe a deprecation timeline beyond the 14 Aug 2026 date.

## What to use instead, and how the approach differs

The README itself points at the alternative: jsrsasign claims no dependency on the W3C Web Cryptography API, and the 11.0.0 notice adds W3C Web Crypto API support. So the natural replacement for signing, verification and key handling in a browser or in modern Node is the platform's own crypto.subtle, which delegates the primitives to the runtime instead of shipping big integer arithmetic in JavaScript. The difference in approach is not cosmetic: jsrsasign implements RSA, ECDSA and DSA in JavaScript on top of jsbn and its own PRNG, while Web Crypto hands the operation to a native implementation and gives you no access to the intermediate ASN.1 structures.

That last clause is the reason some users cannot simply switch. Web Crypto will sign and verify, but it will not parse a CMS SignedData blob, build a CAdES timestamp, or read an OCSP response. jsrsasign's ASN.1 modules will. So the honest split is: for plain sign and verify, the platform API is the better default; for PKI message formats in pure JavaScript, jsrsasign remains one of the few options, and its end-of-support date becomes a scheduling problem rather than a reason to rewrite tomorrow. The README does not name a successor project, and no migration guide to another library appears in the repository documentation.

## Maintenance cost, licence and the upgrade you should plan for now

Maintenance status is easy to state because the project states it. Support ends on 14 Aug 2026, npm packages are deprecated, GitHub Sponsors was disabled on 2026-Apr-14, and the last push was on 2026-08-19. There is no active development to track, so the upgrade cost is not a recurring one; it is a single decision about which version you freeze on. That version should be 11.1.4, the final release, which the news list labels a security fix and the final release.

Upgrading to 11.x is not a drop-in for older code. The 11.0.0 notice lists the removals: Internet Explorer, bower, YUI compressor and the QUnit and mocha test setup. Earlier, 9.0.0 changed certificate and CSR generation and parsing without backward compatibility, and the README points to a migration guide from 8.0.x to 9.0.0. If you are on 8.x, expect two breaking transitions rather than one.

On licensing, the README badge and the LICENSE.txt link indicate the MIT licence, while the repository metadata reports NOASSERTION. That mismatch is worth resolving against LICENSE.txt before you redistribute, and it is the kind of thing a legal reviewer will ask about. Nothing here is legal advice.

The repository also carries SECURITY.md. Given that the project no longer accepts reports in the usual sense, read that file before you assume a vulnerability you find will be fixed upstream.

## Conclusion

Existing deployments that need ASN.1, CMS, CAdES or OCSP from JavaScript are the remaining audience; new projects should not start here, because the README states support ends on 14 Aug 2026 and the npm packages are deprecated. Before anything else, verify that your installed version is 11.1.4 or later and that you never call RSA PKCS#1.5 or RSA-OAEP decryption, which 11.0.0 removed.

## FAQ

### How do I install jsrsasign?

The README gives npm install jsrsasign jsrsasign-util for Node, or a script tag pointing at a CDN build of jsrsasign-all-min.js for browsers. A bower command also appears, but the 11.0.0 notice states bower support was dropped.

### Is jsrsasign still maintained?

No. The README states that effective 14 Aug 2026 support is no longer provided and all versions of the npm package are deprecated, and 11.1.4 on 2026-08-14 is labelled the final release. The repository is not archived and the last push was on 2026-08-19.

### Which jsrsasign version should I install?

11.1.4, the final release, which the news list labels a security fix. Earlier lines are missing fixes listed in the advisory table, including the 10.5.25 and 10.2.0 entries.

### Does jsrsasign support RSA encryption and decryption?

Not for PKCS#1.5 or RSA-OAEP. The 2024-Jan-16 advisory entry for CVE-2024-21484 states that due to the Marvin attack vulnerability those modes are no longer supported from 11.0.0 onward.

### What can I use instead of jsrsasign for signing?

The W3C Web Crypto API, which jsrsasign explicitly avoids depending on and which 11.0.0 added support for. It will not parse or build CMS SignedData, CAdES or OCSP structures, so it does not replace the PKI format modules.

## Sources

- [Issues](https://github.com/kjur/jsrsasign/issues)
- [kjur/jsrsasign on GitHub](https://github.com/kjur/jsrsasign)
- [Project website](https://kjur.github.io/jsrsasign)
- [README](https://github.com/kjur/jsrsasign/blob/master/README.md)
- [Releases](https://github.com/kjur/jsrsasign/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/kjur-jsrsasign
