request security pki generate-key-pair (Security)
Syntax
request security pki generate-key-pair certificate-id certificate-id-name <size (256 | 384 | 1024 | 2048 | 4096 | 521)> <type (dsa | ecdsa | rsa)>
Description
Generate a public key infrastructure (PKI) public/private key pair for a local digital certificate.
Options
certificate-id certificate-id-name | Name of the local digital certificate and the public/private key pair. |
size | Key pair size. The key pair size can be 256, 384, 521, 1024, 2048, or 4096 bits. Key pair sizes of 256, 384, and 521 bits are compatible with ECDSA. For Digital Signal Algorithm (DSA) and Rivest Shamir Adleman (RSA), algorithms the size must be 1024, 2048, or 4096. The default key pair size is 1024 for DSA and 2048 for RSA. The following are supported when ECDSA-521 signatures are used:
|
type | The algorithm to be used for encrypting the public/private key pair:
|
Required Privilege Level
maintenance
Output Fields
When you enter this command, you are provided feedback on the status of your request.
Sample Output
request security pki generate-key-pair
user@host> request security pki generate-key-pair type [xxx] size [xxx] certificate-id test Generated key pair test, key size [xxx] bits
Release Information
Command introduced in Junos OS Release 11.1.
Options to support Elliptic Curve Digital Signature Algorithm (ECDSA) added in Junos OS Release 12.1X45-D10.
521
option to support ECDSA introduced in Junos OS
Release 19.1R1 on SRX5000 line of devices with SRX5K-SPC3 card.