Skip to content

DES / 3DES Encrypt & Decrypt Tool

DES encrypt/decrypt in your browser: single DES, 3DES (2-key/3-key), ECB/CBC, PKCS#7 (Java's PKCS5Padding). Key lengths validated strictly — never silently truncated. Includes an equivalent OpenSSL command. Nothing is uploaded.

No Tracking Runs in Browser Free
Encryption runs entirely in your browser — the key and data you enter never leave this device.

Ciphertext
Equivalent OpenSSL command
—

The command contains the key you entered.

DES test vector from FIPS 81

Computed at build time by the engine this page runs — check your own DES implementation against it.
Key (single DES) 0123456789abcdef
Plaintext 4e6f772069732074
Ciphertext (ECB, no padding) 3fa40e8a984d4815
The DES/3DES engine asserts the FIPS 81 vector and was cross-checked against OpenSSL 3 (des-ede / des-ede3, with single DES verified through the K‖K‖K equivalence) on 3,000+ random combinations across ECB and CBC; the equivalent OpenSSL commands were executed in a real shell for comparison. Library defaults were confirmed by running them and reading source; see alternatives. — Go Tools Security Team · Sep 28, 2026

Written and reviewed by the developers who build the crypto tools. Every ciphertext and byte count on this page is computed by the tool's engine and asserted by tests.

DES quick answers

DES key length

8 / 16 / 24 bytes Single DES: 8 bytes (56 effective bits). 3DES: 16 bytes (2-key) or 24 bytes (3-key). Nominal key material 112/168 bits; NIST security strength about 80/112 bits (SP 800-57). Auto-detected from the byte count; other lengths throw.

FIPS 81 test vector

3fa40e8a984d4815 Key 0123456789abcdef, plaintext "Now is t" (hex 4e6f772069732074): single DES ECB without padding outputs 3fa40e8a984d4815.

How long is the DES IV

8 bytes 8 bytes (16 hex digits), CBC only — ECB uses none. Distinct from AES's 16-byte IV.

What is Java's PKCS5Padding

= PKCS#7 For DES it is PKCS#7 — the same padding algorithm under its historical name (PKCS#5 only defined 8-byte blocks, which happens to be DES's).

Is DES secure today

Legacy interop only No. Single DES retired 2005; 3DES deprecated in SP 800-131A Rev.2 (2023). Legacy interop only — use AES-256 for anything new.

What are DES and 3DES (Data Encryption Standard)?

DES (Data Encryption Standard) is the symmetric block cipher the US standards body adopted in 1977, based on IBM's Lucifer design. It processes 64-bit (8-byte) blocks under a nominal 64-bit key with 56 effective bits, through 16 rounds of a Feistel structure.

3DES (TDEA, Triple DES) chains DES three times to patch the short key: C = E_K3(D_K2(E_K1(P))). The middle pass is a decryption so that K1=K2=K3 collapses the chain to single DES — a deliberate compatibility choice. The 2-key form (K3=K1) has about 112 effective bits and is the most common shape in legacy banking systems.

NIST retired single DES in 2005 (FIPS 46-3 notice) and deprecated 3DES in SP 800-131A Rev.2 (2023). The only reason they still exist is legacy interop: bank clearings, payment gateways and 90s/2000s Java/.NET/PHP systems still run DES-era crypto. New designs should use AES-256.

# OpenSSL single DES (legacy provider)
openssl enc -des-ecb -provider legacy -provider default -K 0123456789abcdef -nopad

# 3-key 3DES CBC + PKCS#7 (default provider)
openssl enc -des-ede3-cbc -K <48 hex digits> -iv <16 hex digits> -base64 -A

What this DES tool does

Strict validation of all three key lengths

8/16/24 bytes are auto-detected as single DES / 2-key / 3-key 3DES; anything else throws. Unlike CryptoJS's silent truncation or openssl enc -K's truncate-and-warn, wrong keys fail loudly — the top source of interop mismatches.

FIPS 81 vector computed at build time

The test vector table at the bottom is derived by the same engine at build time, so crawlers read the reference value without running JS and the printed number can never drift from the interactive one.

Equivalent OpenSSL command

Every parameter combination maps to an openssl enc command that reproduces the result on OpenSSL 3, including the legacy-provider flags for single DES. Send it to the other side to pin down parameter divergence.

GBK plaintext support

DES-era Java getBytes() on a Chinese Windows JDK produces GBK. Both directions here accept GBK, so old-system Chinese plaintext needs no pre-conversion.

Entirely in the browser

Pure TypeScript, zero dependencies, zero network requests. Keys and plaintext never leave the device; works offline once loaded. The only acceptable shape for a key-handling tool.

DES library defaults across languages

Java (JCE)

"DES" defaults to ECB + PKCS5Padding

Cipher.getInstance("DES") equals DES/ECB/PKCS5Padding; "DESede" is 3DES but accepts only 24-byte keys — expand K1‖K2 to K1‖K2‖K1 for 2-key. PKCS5Padding is PKCS#7 for DES. Omitting the IV: encryption picks a random one (retrieve via getIV()), decryption throws "Parameters missing".

PHP (openssl_encrypt)

des-ede3-cbc / des-ede-cbc

Algorithm names follow OpenSSL: des-ede3 is triple ECB, des-ede3-cbc is CBC. $options=0 (default) outputs Base64 text; OPENSSL_RAW_DATA for raw bytes. Short keys are silently zero-padded; an empty IV warns and then encrypts with a zero IV.

OpenSSL 3 (openssl enc)

-des-ede3-cbc works by default

Single DES needs -provider legacy -provider default (some builds omit legacy entirely). -K/-iv take hex; PKCS#7 by default, -nopad to disable. -K truncates overlong keys with a warning.

CryptoJS

Silently truncates illegal key lengths

An 8-byte raw key (WordArray) works; wrong lengths are silently zero-padded or truncated (4 bytes padded, 10 truncated — no error). A string "key" runs key derivation (MD5 + random salt, Salted__-prefixed output, different every time). CBC with no IV is a TypeError crash, not a zero IV. TripleDES with an 8-byte key silently becomes single DES.

.NET

TripleDES defaults to CBC + PKCS7

TripleDESCryptoServiceProvider: Mode=CBC, Padding=PKCS7, Key of 16 or 24 bytes (DES takes 8). .NET rejects weak keys (parity is normalized first, then checked against the weak-key table — a zero key throws) while every other library accepts them. Watch this when migrating.

Go (crypto/des)

Explicit mode wiring

des.NewCipher gives the raw 8-byte-key block interface; you wrap it in cipher.NewCBCEncrypter etc. yourself. 3DES is des.NewTripleDESCipher (24 bytes). IV length is checked more strictly than in most languages.

DES encryption examples

FIPS 81 test vector (single DES, ECB, no padding)

Key 0123456789abcdef, plaintext (hex) 4e6f772069732074
3fa40e8a984d4815

The plaintext is the ASCII string "Now is t". This is the textbook FIPS 81 vector, and the table at the bottom of the page is computed at build time by the same engine — if your DES implementation does not produce this value for these inputs, it has a bug.

2-key 3DES + CBC + PKCS#7: UTF-8 plaintext to Base64

Key 0123456789abcdeffedcba9876543210 (16 bytes), IV fedcba9876543210, plaintext: DES interop test: order 20260927-0042
QmnMoewSecp7Z7cr/w3/4AjM9lpFo1swc4dfLNH5UkgCwU5n7WIdKA==

A 16-byte key is treated as 2-key 3DES (K1 = first 8 bytes, K2 = last 8, K3 = K1 — the EDE2 assembly). PKCS#7 over an 8-byte block is exactly what Java calls "PKCS5Padding" for DES: same scheme, only the block size differs.

3-key 3DES + CBC + PKCS#7

Key 0123456789abcdef23456789abcdef010456789abcdef012 (24 bytes), IV fedcba9876543210, plaintext: hello des
DhDQX9sfxKOirZ8eyqT7Jg==

A 24-byte key is the full three-key EDE3: C = E_K3(D_K2(E_K1(P))). Of the three key lengths this is the only form with no degenerate equivalent — both 2-key and K1=K2=K3 collapse to weaker ciphers.

How to use this DES encrypt/decrypt tool

  1. 1

    Pick mode and padding

    For Java DES/ECB/PKCS5Padding choose ECB + PKCS#7; for openssl enc -des-ede3-cbc choose CBC + PKCS#7. Old PHP mcrypt code typically uses Zero padding.

  2. 2

    Enter the key (8/16/24 bytes)

    The byte count selects the cipher: 8 = single DES, 16 = 2-key 3DES, 24 = 3-key 3DES. Choose Hex, Text or Base64; the badge shows the real byte count and the detected shape. Wrong lengths throw — nothing is ever truncated.

  3. 3

    For CBC, enter the 8-byte IV

    ECB needs no IV. The IV must be exactly 8 bytes — 16 hex digits, not AES's 32. The Random button produces a fresh one.

  4. 4

    Paste and get live results

    Encrypting: enter text (UTF-8/GBK) or hex. Decrypting: paste Base64 or hex ciphertext. Results update as you type, with one-click copy and a round-trip check via the Decrypt-this button.

  5. 5

    Take the equivalent OpenSSL command to the other side

    The collapsible panel gives an openssl enc command that reproduces the current result (key included; single-DES commands carry -provider legacy -provider default). Send it to whoever you are interoperating with — the fastest way to settle whose parameter is wrong.

Why DES decryption fails

Key length is not 8/16/24

A "DES key" of 32 hex characters is 16 bytes — that is 2-key 3DES, not single DES. Conversely, feeding a 24-byte key to a 2-key-only system fails too.

✗ Wrong
Key 0123456789abcdeffedcba9876543210 (16 bytes) with single DES selected → error "the key must be exactly 8 bytes"
✓ Correct
The same key as 16 bytes (2-key 3DES) → decrypts cleanly

PKCS5 vs PKCS7 name confusion

Java writes "PKCS5Padding" for DES but executes the PKCS#7 algorithm (PKCS#5 only ever defined 8-byte-block padding, which equals DES's block, so the name stuck). Selecting None or Zero against a JCE ciphertext always fails.

✗ Wrong
JCE `DES/ECB/PKCS5Padding` ciphertext decrypted as "no padding" → trailing garbage or a bad-padding error
✓ Correct
Select PKCS#7 (Java PKCS5Padding) → clean output

Copying the AES IV length (16 bytes)

DES's block is 8 bytes, so its IV is 8 bytes too. Pasting a 32-hex-digit IV from AES code fails the length check; an 8-hex-digit IV gets zero-padded and misread.

✗ Wrong
IV 00000000000000000000000000000000 (32 hex digits) → error "IV must be 8 bytes"
✓ Correct
IV 0000000000000000 (16 hex digits) → accepted

Wrong CBC IV: only the first 8-byte block is garbage

Decrypting multi-block ciphertext with a wrong IV does not error — only the first 8-byte block is garbage, the rest decrypts fine (the IV only reaches block one, and the padding check lives in the last block). When you see "first few characters garbled, rest fine", check the IV before the key; single-block ciphertext instead breaks the padding and throws bad decrypt.

✗ Wrong
Multi-block ciphertext + wrong IV → first 8 bytes garbled, rest normal — misread as "wrong key"
✓ Correct
Change only the IV (key untouched) → first block recovers, confirming the IV was the issue

openssl enc -K silently truncates long keys

-K keeps only the bytes it needs and prints a one-line warning that scripts swallow. When the other side says "the key is these 48 hex digits" but actually encrypted with the first 16, decrypting with the full key fails.

✗ Wrong
Shell: `-K <49 hex digits>` → "hex string is too long, ignoring excess" lost in the pipeline
✓ Correct
Use this tool's equivalent command to generate a correct-length `-K`, then compare key bytes with the other side

Single DES fails on OpenSSL 3 with "unsupported"

The default OpenSSL 3 provider has no des-ecb/des-cbc; running it bare throws digital envelope routines::unsupported. Add -provider legacy -provider default, or use des-ede3 with K‖K‖K (algebraically single DES).

✗ Wrong
openssl enc -des-ecb -K … → Error: unsupported
✓ Correct
openssl enc -des-ecb -provider legacy -provider default -K … (or des-ede3-ecb -K <K‖K‖K>)

When you need online DES encryption

Debugging legacy-system message crypto
Bank clearings, POS gateway MAC computation and old ERP interface encryption still run DES/3DES. Paste the message and key here to check "is the key right, which mode, which padding" without standing up a Java or PHP environment.
Migrating Java / PHP / .NET legacy code
Compare Cipher.getInstance("DES/ECB/PKCS5Padding") output or openssl_encrypt(..., 'des-ede3-cbc', ...) output against this tool byte for byte before switching. 2-key/3-key shapes are detected from the key length, so there is nothing to guess.
Security audits and teaching
Demonstrate ECB's pattern leakage (equal plaintext blocks → equal ciphertext blocks), verify 3DES degeneration (K1=K2=K3 collapses to single DES), and check the FIPS 81 vector — standard fare in pentest reports and cryptography coursework.
Generating example ciphertexts for docs
When an internal wiki or API doc needs a reproducible example, compute it here with a fixed key and IV — readers can verify it with the equivalent OpenSSL command, and no production data gets pasted around.

DES / 3DES and block cipher modes explained

Block and key
DES processes 64-bit blocks through 16 Feistel rounds, each with a 48-bit subkey derived from the 56-bit master key by PC-1/PC-2 compression permutations and scheduled rotations. The eight S-boxes are the only source of nonlinearity; their design criteria have never been fully published.
The 3DES EDE assembly
C = E_K3(D_K2(E_K1(P))). The middle decryption makes K1=K2=K3 collapse to single DES — a backward-compatibility goal. The 2-key form has 2×56=112 bits of nominal key material but a NIST security strength of about 80 bits (SP 800-57 Part 1); 3-key is nominally 168 bits with a strength of 112 bits (deprecated).
ECB and CBC
ECB encrypts blocks independently — equal plaintext blocks yield equal ciphertext blocks, a visible pattern leak that 8-byte blocks make worse than AES-ECB. CBC mixes the previous ciphertext block (the IV for the first) into the plaintext before encrypting, and was the mainstream choice for DES-era banking. Both modes produce ciphertext that is a multiple of 8 bytes.
Padding: PKCS#7 / Zero / None
PKCS#7 appends n bytes of value n for whatever is missing (3 missing → 03 03 03) and pads a full block with a whole extra block — this is Java's "PKCS5Padding" for DES. Zero padding fills with 0x00 and is lossy when the plaintext genuinely ends in 0x00. None requires an exact multiple of 8.
OpenSSL 3's legacy provider
OpenSSL 3 moved single DES into a legacy provider that is off by default: the CLI needs -provider legacy -provider default, and some builds (including Node's bundled OpenSSL) omit it entirely. 3DES (des-ede/des-ede3) stays in the default provider. This tool's pure-TS engine is unaffected.

Using DES correctly (legacy interop)

Never use DES for new systems, in any shape
Single DES's 56 bits are brute-forceable; the 64-bit block carries the Sweet32 birthday bound (CVE-2016-2183), and NIST caps one key bundle at ≈8 MB (2²⁰ blocks) of plaintext; 2-key is Disallowed, 3-key encryption after 2023. Use AES-256 for anything new. This tool exists to read and safely migrate legacy systems.
In legacy interop, byte-identical first
When touching an old system, first reproduce the old parameters' ciphertext here byte for byte, then change code. Confirm key length, mode, padding and IV source (fixed vs random, header vs out-of-band) before switching algorithms.
Do not reuse IVs, even in legacy systems
Reusing a CBC IV under the same key exposes the relation between the first blocks of two plaintexts. If a legacy protocol mandates a fixed IV, record it as a defect in the migration list — do not inherit it as a convention.
Keep keys out of source code
DES-era systems routinely hardcode keys in plaintext source or config. When auditing one, put "how the key is stored" next to "which algorithm" in the report — in most breaches the former was the actual hole.

DES encrypt/decrypt FAQ

DES decryption fails with "bad decrypt" or a padding error — what do I check?
Decryption requires every parameter to match the encrypting side: the key bytes, the key length (8/16/24), the mode (ECB/CBC), the IV, the padding, and whether the ciphertext is hex or Base64. The two most common traps: key length mismatch (a "DES key" of 32 hex characters is 16 bytes — that is 2-key 3DES, not single DES) and padding name confusion (Java's PKCS5Padding IS PKCS#7 for DES — don't pick None). The collapsible panel on the right shows an equivalent OpenSSL command for the current settings; sending it to the other side is the fastest way to find the divergence.
How long is a DES key? And 3DES?
Single DES: 64 bits nominal (8 bytes, 56 effective — one bit per byte is a parity bit). 3DES comes in two shapes: 2-key (16 bytes, K1‖K2 with K3=K1) and 3-key (24 bytes, K1‖K2‖K3). Their nominal key material is 112/168 bits, but the NIST security strength (SP 800-57 Part 1 Rev.5 Table 2) is about 80 and 112 bits respectively — and the 3-key shape is deprecated too. This tool identifies the shape from the byte count; anything that is not 8/16/24 throws — CryptoJS and openssl enc -K silently truncate or zero-pad instead, which is the number-one source of interop failures.
What is the IV and how long is it for DES?
The IV is the 8-byte value CBC mixes into the first block; ECB does not use one. It must be exactly 8 bytes (16 hex digits or 8 ASCII characters). Note that DES's IV is 8 bytes while AES's is 16 — copying an AES IV length over fails immediately. Never reuse an IV under the same key.
What does Java's DES/ECB/PKCS5Padding map to in this tool?
ECB mode + PKCS#7 padding. In the JCE, "PKCS5Padding" for DES executes the generic PKCS#7 algorithm — PKCS#5 only ever defined padding for 8-byte blocks, which happens to be DES's. Java Cipher.getInstance("DES/ECB/PKCS5Padding") output decrypts here with ECB + PKCS#7 and an 8-byte single-DES key. ⚠️ Java's 3DES (DESede) accepts only 24-byte keys — for the 2-key shape you must expand K1‖K2 to K1‖K2‖K1 yourself.
How do PHP's des-ede3 algorithm names map?
PHP borrows OpenSSL's names: des-ede3-cbc is 3-key 3DES + CBC, des-ede3-ecb is 3-key + ECB; des-ede-cbc is the 2-key shape. A 24-byte key selects 3-key, 16 bytes selects 2-key.
What are the parity bits in a DES key? Are they checked?
The low bit of each key byte is defined as a parity bit, so the true 56-bit key sits inside 64 bits. FIPS 46-3 does not require checking it — OpenSSL, Java and this tool all ignore it; any 8 bytes work, and changing parity bits does not change the ciphertext. .NET is the exception: it normalizes parity first and then checks a weak-key table, so zero and other weak keys are rejected by .NET while every other library encrypts happily — a trap that fires only when migrating test keys from Java/OpenSSL to .NET.
What happens in 3DES when K1 = K2?
In 2-key 3DES, K3 always equals K1; if K1 = K2 as well, the whole EDE chain collapses to single DES: E_K(D_K(E_K(P))) = E_K(P). The same happens when all three 8-byte components of a 24-byte key are identical. This tool still encrypts (interop first), but the real strength is then single-DES 56 bits, not 3DES.
Is DES still secure?
No — it is for legacy interop only. NIST withdrew single DES on 2005-05-19 (56-bit keys are brute-forceable; EFF's Deep Crack did it in 56 hours in 1998, 22 hours the next year with distributed.net). SP 800-131A Rev.2 lists 2-key TDEA encryption as Disallowed, and 3-key encryption as Disallowed after 2023-12-31 (decryption stays "Legacy use", kept only for reading historical data); SP 800-67 itself was withdrawn on 2024-01-01. The small 64-bit block also carries the Sweet32-class birthday bound (CVE-2016-2183) — NIST caps a single key bundle at 2²⁰ blocks (≈8 MB) of plaintext. Use AES-256 for anything new. This tool exists because banking clearings, payment gateways and old Java/.NET systems still run DES-era messages — fixing them starts with being able to read them.
Why does my 3DES result differ from Java/PHP?
Check in order of hit rate: ① key length — the other side's "32-hex DES key" is 16 bytes (2-key 3DES), you decrypted as single DES; ② mode — Java's bare "DES" defaults to ECB; OpenSSL's mode-less names des-ede3/des-ede are ECB (the CBC alias is -des3); PHP's openssl_encrypt requires an explicit algorithm name — the confusion there is that its default output is Base64 text, not raw bytes; ③ padding — old PHP mcrypt often used Zero padding, JCE uses PKCS#5/#7; ④ encoding — hex vs Base64, and case; ⑤ the CryptoJS password trap — passing a string as the "key" makes it run key derivation (MD5 + random salt, output prefixed Salted__, different every time), which is not the raw key at all — the top cause of "same code, different results every run". This tool lets you flip each one; the equivalent OpenSSL command on the right can be sent to the other side to reproduce.
ECB or CBC — which should I use?
Whatever the system you are talking to requires — legacy interop does not get a vote. If you do get to choose, always CBC with a random IV: ECB encrypts equal plaintext blocks to equal ciphertext blocks, and DES's small 8-byte blocks leak patterns even more visibly than AES-ECB. DES-era banking protocols use both; check the protocol document first.
Does this work offline? Is my data uploaded?
All computation happens in your browser (pure TypeScript, zero dependencies, zero network requests); keys and plaintext never leave the device. Once the page has loaded you can go offline and keep working. That is the only acceptable shape for a key-handling tool.
2-key or 3-key 3DES — which is more common in legacy systems?
2-key (16 bytes) is more common: banks and the payment industry deployed 16-byte-key hardware for compatibility, and SP 800-67 kept a separate (earlier) deprecation date for it. So a "3DES key" of 32 hex characters is most likely the 2-key shape. This tool detects the shape from the byte count automatically.

Related Tools

View all tools →