# Public/Private Key > [HTML Version](publicprivatekey.htm) CRYPTO's opcode CRYPTOP\_GENPUBKEY is used to generate a public/private key file pair. Its syntax differs slightly from the other opcodes: **xcall CRYPTO, CRYPTOP\_GENPUBKEY, status, pubkeyfile, decoding, privkeyfile, encoding, cflags, cipher, passphrase, keybits, cmode** **Parameters** _status_ Returns the result status of the operation: >= 0 for success (number of bytes output to dst), <0 for errors. See CRYPTERR\_xxx in [CRYPTO.DEF in SOSLIB:\[907,16\]](https://bitbucket.org/microsabio/soslib/src/master/907016/crypto.def). _pubkeyfile_ and _privkeyfile_ (in place of the _src_ and _dst_ parameters for other opcodes) must be set to the filespecs for the generated public and private key files. _decoding_ and en_coding_ should be ""; there are no options for this opcode. _cflags_ should be set to CRYPF\_NONE, since output is always to file _cipher_ should be set to either CRYPTO\_CIPHER\_RSA or CRYPTO\_CIPHER\_DSA _passphrase_ (in place of the _key_ parameter for other opcodes) must be set to the passphrase to encrypt the private key file or "" for none. _keybits_ must be a multiple of 64, between 384 and 4096. _cmode_ determines the format of the public key file: • CRYPTO\_MODE\_OPENSSH (0) OpenSSH format • CRYPTO\_MODE\_RFC4716 (3) RFC 4716 format **Comments** For Unix login authentication, the most typical options would be: cipher = CRYPTO\_CIPHER\_RSA keybits = 2048 cmode = CRYPTO\_MODE\_OPENSSH