# Public/Private Key
> [HTML Version](publicprivatekey.htm)
CRYPTO's opcode CRYPTOP\_GENPUBKEY is used to generate a public/private key file pair. Its syntax differs slightly from the other opcodes:
**xcall CRYPTO, CRYPTOP\_GENPUBKEY, status, pubkeyfile, decoding, privkeyfile, encoding, cflags, cipher, passphrase, keybits, cmode**
**Parameters**
_status_
Returns the result status of the operation: >= 0 for success (number of bytes output to dst), <0 for errors. See CRYPTERR\_xxx in [CRYPTO.DEF in SOSLIB:\[907,16\]](https://bitbucket.org/microsabio/soslib/src/master/907016/crypto.def).
_pubkeyfile_ and _privkeyfile_ (in place of the _src_ and _dst_ parameters for other opcodes)
must be set to the filespecs for the generated public and private key files.
_decoding_ and en_coding_
should be ""; there are no options for this opcode.
_cflags_
should be set to CRYPF\_NONE, since output is always to file
_cipher_
should be set to either CRYPTO\_CIPHER\_RSA or CRYPTO\_CIPHER\_DSA
_passphrase_ (in place of the _key_ parameter for other opcodes)
must be set to the passphrase to encrypt the private key file or "" for none.
_keybits_
must be a multiple of 64, between 384 and 4096.
_cmode_
determines the format of the public key file:
• CRYPTO\_MODE\_OPENSSH (0) OpenSSH format
• CRYPTO\_MODE\_RFC4716 (3) RFC 4716 format
**Comments**
For Unix login authentication, the most typical options would be:
cipher = CRYPTO\_CIPHER\_RSA
keybits = 2048
cmode = CRYPTO\_MODE\_OPENSSH