$manlookup

openssl-gendsa

(1ssl)

generate a DSA private key from a set of parameters

User commands12 optionsopenssl 3.5.6-1~deb13u2
openssl gendsa [-help] [-out filename] [-passout arg] [-aes128] [-aes192] [-aes256] [-aria128] [-aria192] [-aria256] [-camellia128] [-camellia192] [-camellia256] [-des] [-des3] [-idea] [-verbose] [-quiet] [-rand files] [-writerand file] [-engine id] [-provider name] [-provider-path path] [-provparam [name:]key=value] [-propquery propq] [paramfile]

Options

12
-help

Print out a usage message.

-outfilename

Output the key to the specified file. If this argument is not specified then standard output is used.

-passoutarg

The passphrase used for the output file. See openssl-passphrase-options(1).

-aes128-aes192-aes256-aria128-aria192-aria256-camellia128-camellia192-camellia256-des-des3-idea

These options encrypt the private key with specified cipher before outputting it. A pass phrase is prompted for. If none of these options is specified no encryption is used. Note that all options must be given before the paramfile argument.

-verbose

Print extra details about the operations being performed.

-quiet

Print fewer details about the operations being performed, which may be handy during batch scripts and pipelines.

-rand-writerandfiles

See "Random State Options" in openssl(1) for details.

-engineid

See "Engine Options" in openssl(1). This option is deprecated.

-providername

-provider-pathpath

-provparam[name:]key=value

-propquerypropq

See "Provider Options" in openssl(1), provider(7), and property(7).

DESCRIPTION

This command generates a DSA private key from a DSA parameter file (which will be typically generated by the openssl-dsaparam(1) command).

NOTES

DSA key generation is little more than random number generation so it is much quicker that RSA key generation for example.

HISTORY

The -engine option was deprecated in OpenSSL 3.0.

See also