request security pki generate-key-pair (Security)
Command introduced in Junos OS Release 11.1.
Options to support Elliptic Curve Digital Signature Algorithm (ECDSA) added in Junos OS Release 12.1X45-D10.
521 option to support ECDSA introduced in Junos OS Release 19.1R1 on SRX5000 line of devices with SRX5K-SPC3 card.
Generate a public key infrastructure (PKI) public/private key pair for a local digital certificate.
The following are supported when ECDSA-521 signatures are used:
Load a complete certificate, which is generated using an external tool like OpenSSL into PKI.
Manually generate a Certificate Signing Request (CSR) for a local certificate and sending the CSR to a (Certificate Authority) CA server to enroll.
Automatic enroll with CA server.
dsa— DSA encryption
rsa—RSA encryption (default)
Required Privilege Level
List of Sample Outputrequest security pki generate-key-pair
When you enter this command, you are provided feedback on the status of your request.
request security pki generate-key-pair
user@host> request security pki generate-key-pair type [xxx] size [xxx] certificate-id test
Generated key pair test, key size [xxx] bits