Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?


request security key-pair



(Encryption interface on M Series and T Series routers and EX Series switches only) Generate a public and private key pair for a digital certificate.


The request security-certificates command is deprecated and are not available with Junos in FIPS mode because security certificates are not compliant with the NIST SP 800-131A standard.



Name of a file in which to store the key pair.

size key-size

(Optional) Key size, in bits. The key size can be 512, 1024, or 2048. The default value is 1024.


(Optional) Algorithm used to encrypt the key:

  • rsa—RSA algorithm. This is the default.

  • dsa—Digital signature algorithm with Secure Hash Algorithm (SHA).

Required Privilege Level


Output Fields

When you enter this command, you are provided feedback on the status of your request.

Sample Output

request security key-pair

Release Information

Command introduced before Junos OS Release 7.4.