# How to make a password-protected private key via REST

**URL:** <https://community.f5.com/t/how-to-make-a-password-protected-private-key-via-rest/72690>\
**Category:** Technical Forums\
**Tags:** devops\
**Created:** [July 12, 2023, 12:20am UTC](https://community.f5.com/t/how-to-make-a-password-protected-private-key-via-rest/72690 "2023-07-12T00:20:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wyko](https://avatars.discourse-cdn.com/v4/letter/w/dc4da7/32.png) [@Wyko](https://community.f5.com/u/Wyko)\
**Post date:** [July 12, 2023, 12:20am UTC](https://community.f5.com/t/how-to-make-a-password-protected-private-key-via-rest/72690/1 "2023-07-12T00:20:05Z")

</div>

Hey everyone!

Does anyone know how to use a REST command to create a password protected key? I tried the following, but it gave me the error:

```bash
{"code":400,"message":"\"passphrase\" may not be specified in the context of the \"create\" command. \"passphrase\" may be specified using the following commands: install","errorStack":[],"apiError":26214401}

```

```python
payload = {
    "name": f"{fqdn}-key-{datetime.utcnow().strftime('%Y%m%d%H%M%S')}.key",
    "commonName": options.common_name,
    "keySize": options.key_size,
    "keyType": "rsa-private",
    "options": [{"gen-csr": "www.testing.com"}],
    "organization": options.organization,
    "city": options.city,
    "state": options.state,
    "emailAddress": options.email,
    "subjectAlternativeName": sans,
    "passphrase": password,
    "securityType": "password",
}

r = await ltm.post("mgmt/tm/sys/crypto/key", json=payload, raise_err=False)

```

---

<div class="post-metadata">

**Author:** ![JRahm](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/jrahm/32/3327_2.png) [@JRahm](https://community.f5.com/u/JRahm)\
**Post date:** [July 12, 2023, 10:28pm UTC](https://community.f5.com/t/how-to-make-a-password-protected-private-key-via-rest/72690/2 "2023-07-12T22:28:23Z")

</div>

Hi&nbsp; @Wyko ,&nbsp;I could be off-base, but I don’t think you can create the key this way. I believe you need to create the key from command line, either locally on a box and upload it to BIG-IP, or create it on command line on BIG-IP itself. Once that step is done, then you can create the file reference to that key with the REST methods.

That said, I would not recommend using the **/tm/sys/crypto/key** method, as the **/tm/sys/crypto** methods have been deprecated for a while, but rather the **/tm/sys/file/ssl-key** method instead. When using the latter method, you’ll want to define sourcePath attribute like “ **file:///var/config/rest/downloads/my.key** ” or whereever you uploaded/created the key. So the data that you would **POST** to **/tm/sys/file/ssl-key** would look something like (using the bigrest python iControl REST wrapper here):

```python
from bigrest.bigip import BIGIP

b = BIGIP('mybigip.local', 'admin', 'admin', session_verify=False)

key_data = {'name': 'testkey.key',
            'keySize': 2048,
            'keyType': 'rsa-private',
            'passphrase': 'encrypted passphrase here',
            'securityType': 'password',
            'sourcePath': 'file:///var/config/rest/downloads/mytestkey.key'
            }
response = b.create('/mgmt/tm/sys/file/ssl-key', key_data)

```

This assumes of course you’ve created the key and moved it or uploaded it to the BIG-IP /var/config/rest/downloads folder.

---

<div class="post-metadata">

**Author:** ![Wyko](https://avatars.discourse-cdn.com/v4/letter/w/dc4da7/32.png) [@Wyko](https://community.f5.com/u/Wyko)\
**Post date:** [December 14, 2023, 9:55am UTC](https://community.f5.com/t/how-to-make-a-password-protected-private-key-via-rest/72690/3 "2023-12-14T09:55:38Z")

</div>

Unfortunately that would still require manual intervention. I am looking for a solution that can be fully automated. Any ideas?

---

<div class="post-metadata">

**Author:** ![phildotchon](https://avatars.discourse-cdn.com/v4/letter/p/a6a055/32.png) [@phildotchon](https://community.f5.com/u/phildotchon)\
**Post date:** [August 3, 2025, 12:43pm UTC](https://community.f5.com/t/how-to-make-a-password-protected-private-key-via-rest/72690/4 "2025-08-03T12:43:04Z")

</div>

Hi @JRahm

> the **/tm/sys/crypto** &nbsp;methods have been deprecated for a while, but rather the&nbsp; **/tm/sys/file/ssl-key** method instead.

I’m struggling to believe this, can you tell me where this depreciation is documented? The **/tm/sys/file/ssl-key** method seems to not actually allow the generation of a key withing the F5, it only allows one to be imported from elsewhere. If I try to create new by just specifying a name and key size, I get

```json
"code": 400,
"message": "source-path is required.",
"errorStack": [],
"apiError": 26214401

```

---

<div class="post-metadata">

**Author:** ![JRahm](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/jrahm/32/3327_2.png) [@JRahm](https://community.f5.com/u/JRahm)\
**Post date:** [August 5, 2025, 5:12pm UTC](https://community.f5.com/t/how-to-make-a-password-protected-private-key-via-rest/72690/5 "2025-08-05T17:12:13Z")

</div>

They sorta work in some scenarios, but when I was working on the imperative sdk years ago I was told to focus on the file commands as the crypto ones were deprecated. Also having a hard time finding that documented anywhere. I’m poking around on this, will let you know if I turn anything up.
