You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于openssl genrsa命令中passout参数的作用及具体示例咨询

Understanding the passout Parameter in openssl genrsa

Hey there! Let's clear up the confusion around the passout parameter and that "output file password source" line from the OpenSSL docs.

First, the core purpose: When you generate an RSA private key with openssl genrsa, the passout parameter controls how OpenSSL gets the password used to encrypt your output private key file. That "password source" phrase just refers to where the tool should pull the password from—instead of making you type it interactively.

Here are concrete examples of the most common use cases:

  • Directly specify the password in the command line (not recommended for production)
    This uses the pass: prefix to pass the password directly in the command:

    openssl genrsa -out private_key.pem -passout pass:MySecurePass123 2048
    

    Note: This is insecure because the password will be stored in your shell's command history.

  • Pull the password from an environment variable
    First set an environment variable with your password, then reference it with env::

    # Set the variable first (works in bash/zsh)
    export KEY_PASSWORD="MyEnvPass456"
    # Generate the key
    openssl genrsa -out private_key.pem -passout env:KEY_PASSWORD 2048
    

    This is safer than command-line input since the password doesn't show up in history.

  • Read the password from a file
    Create a file with your password (make sure it only has one line with the password), then use the file: prefix:

    # Create the password file (restrict permissions to keep it secure)
    echo "MyFilePass789" > password.txt
    chmod 600 password.txt
    # Generate the key
    openssl genrsa -out private_key.pem -passout file:password.txt 2048
    

    Always lock down the password file with strict permissions so only you can access it.

  • Read the password from standard input
    Use the stdin: prefix to have OpenSSL read the password from standard input. You can pipe it in or type it manually:

    # Pipe the password directly
    echo "MyStdinPass012" | openssl genrsa -out private_key.pem -passout stdin 2048
    

    Or run the command and type the password when prompted (though this behaves similarly to not using passout at all):

    openssl genrsa -out private_key.pem -passout stdin 2048
    

If you skip the passout parameter entirely, OpenSSL will prompt you to enter and confirm the password interactively—this is the safest default for most scenarios.

内容的提问来源于stack exchange,提问作者Tom Stevens

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 22:52:48