In order to improve the efficiency of existing multi-signature schemes based on bilinear pairings and relieve the inherent key escrow problems in the identity-based multi-signature scheme,an RSA-based certificateless multi-signature scheme was proposed,which was constructed on Zhang and Mao’s certificateless signature scheme.In this scheme,only L+9 exponential operations 5L+1 multiplications are needed, and the signature length is (L+2)|n|,where L is the number of signers and |n| is the binary length of the system parameter n.The proposal is free of key escrow and secure in the random oracles model.