Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

CSR Generator

A key and a CSR for your SSL certificate, made on your device — the key never leaves it.

Security No upload Works offline Free, no sign-up

Certificate details

Key type

Accepted everywhere — the usual choice for TLS certificates. 112-bit security (NIST SP 800-57).

Such as www.example.com or *.example.com. For a client certificate, a person or service name.

One per line (or separated by commas): more domains, wildcards such as *.example.com, or IP addresses.

Organisation (only for OV and EV certificates — leave empty for domain-validated ones)

Two letters (ISO 3166-1), such as IN, US, GB or DE.

In full, not abbreviated.

More options

Automatic: SHA-256, or SHA-384 for P-384 keys.

Public CAs no longer accept it in TLS certificates.

Not used in TLS certificates; some private CAs want it.

For S/MIME or private PKI (for example SPIFFE IDs). Public TLS CAs do not accept them.

Ask for extended key usage (private CAs)

Adds an AES-256 encrypted copy of the key. Web servers usually use the unencrypted key.

Next steps

About the CSR Generator

Get a certificate signing request (CSR) for an SSL/TLS certificate without a command line: choose the key type, enter your domain names and organisation details, and the page creates a new private key and a PKCS#10 CSR (RFC 2986) with your names in the Subject Alternative Name extension — the part browsers check. Give the CSR to your certificate authority; keep the key on your server.

The key is made by your browser’s Web Crypto API and never leaves this page: nothing is uploaded or stored. Each request is decoded again and its signature verified before it is shown, and its contents are encoded exactly as openssl req writes them — the page shows the equivalent OpenSSL command and an openssl.cnf file, so you can also make the same request on the server itself.

How to use it

  1. Choose the key type. RSA 2048-bit works with every CA and server; ECDSA P-256 is smaller and faster and is accepted by the major public CAs.
  2. Enter the common name — your main domain, such as www.example.com — and any other names the certificate must cover, one per line (example.com, *.example.com, an IP address).
  3. For an organisation-validated (OV) or EV certificate, add the organisation, city, state and two-letter country code exactly as registered. Domain-validated certificates need none of them.
  4. Press Generate key and CSR. A 4096-bit RSA key can take several seconds.
  5. Download or copy the CSR (.csr) for your CA, and **save the private key (.key) now** — it exists only in this tab, and without it the certificate cannot be installed.

Examples

A certificate for a website with and without www
Input
Common name: example.com · Other names: www.example.com · RSA 2048-bit
Result
openssl req -new -newkey rsa:2048 -nodes -keyout example.com.key -out example.com.csr -sha256 \
  -subj '/CN=example.com' \
  -addext 'subjectAltName=DNS:example.com,DNS:www.example.com'

The page makes the same request in your browser; the command is there to repeat it on a server.

A wildcard certificate
Input
Common name: *.example.com · Other names: example.com
Result
SANs: DNS:*.example.com, DNS:example.com

A wildcard covers one level of subdomains (shop.example.com) but not example.com itself, so add both.

An OV request for a company
Input
C=IN · ST=Karnataka · L=Bengaluru · O=Example Pvt Ltd · CN=www.example.com
Result
Subject: C=IN, ST=Karnataka, L=Bengaluru, O=Example Pvt Ltd, CN=www.example.com

Common uses

  • Ordering an SSL certificate from a CA or hosting panel that asks you to paste a CSR.
  • Renewing a certificate with a new key, or adding names (SANs) to it.
  • Creating requests for internal servers and devices to sign with a company (private) CA, including IP addresses and client-authentication certificates.
  • Learning what openssl req needs: the page writes the command and a reusable openssl.cnf for every request.

Which key type and size?

  • RSA 2048-bit — accepted by every certificate authority, server and client. 112-bit security in NIST SP 800-57, enough for certificates that last months.
  • RSA 3072 or 4096-bit — more margin for keys you keep for years, at the cost of slower TLS handshakes; 4096-bit keys take a while to generate.
  • ECDSA P-256 — 128-bit security in a much smaller key with faster handshakes; supported by the major public CAs, browsers and servers.
  • ECDSA P-384 — 192-bit security, for policies that require it.

All of them meet the CA/Browser Forum’s rules for public certificates: RSA keys of at least 2048 bits, ECDSA on P-256, P-384 or P-521 (Baseline Requirements §6.1.5). The CSR is signed with SHA-256 (SHA-384 for P-384 keys).

Which fields do certificate authorities use?

  • Names (SANs): what the certificate will be valid for. Public CAs check that you control each domain before issuing.
  • Common name (CN): older software still shows it, and many CA order forms read your main domain from it, but clients no longer use it to identify a server (RFC 9525). If it is a host name, it is also listed as a SAN (unless you untick that), as the Baseline Requirements require (§7.1.4.3); a single word such as localhost or a person’s name is not, and the page says so.
  • Organisation, locality, state, country: used only for organisation-validated (OV) and EV certificates, after the CA has verified them. For domain-validated certificates the CA ignores them.
  • Organizational unit (OU) and email address: public CAs may no longer put OU in TLS certificates (§7.1.2.7.4), and an email address in the subject plays no part in TLS. Leave them empty unless a private CA needs them.
  • Extended key usage: public CAs decide this themselves; asking for TLS server or client authentication only matters for a private CA that honours requests.

Field lengths follow the upper bounds of RFC 5280 (Appendix A): up to 64 characters for the common name, organisation and unit, 128 for the city and state. The country is always a two-letter code.

Names public CAs will not accept

Publicly trusted certificates may only contain registered domain names and public IP addresses (BR §7.1.2.7.12). Internal names (anything not ending in a top-level domain in the IANA root zone, such as .local or .lan), private and reserved addresses (10.x, 192.168.x, 127.0.0.1 and the other blocks in IANA’s special-purpose registries), reverse-DNS names (ending in in-addr.arpa or ip6.arpa) and names with underscores are flagged: the request still works with a private CA, but a public CA will refuse it. International domain names are converted to their xn-- A-label form, which certificates require.

After the certificate arrives

Install the certificate with the private key from this page — they belong together. Most servers also need the CA’s intermediate certificate: put your certificate first, then the intermediate, in one file. Check the result in the SSL Certificate Decoder. To check that a certificate matches the key, compare its Public key SHA-256 in the decoder with the one this page shows for your CSR, or run openssl x509 -in certificate.crt -noout -pubkey | openssl pkey -pubin -outform DER | openssl sha256 and openssl pkey -in example.com.key -pubout -outform DER | openssl sha256 — the hashes must be equal.

Limitations

  • The private key exists only in this browser tab. If you close or reload the page before saving it, it is gone and you must make a new CSR.
  • For long-lived production keys, many organisations prefer to generate the key on the server (or in the HSM or key vault) that will use it, so it never exists anywhere else — the OpenSSL command on this page does exactly that.
  • Windows IIS creates CSRs in its own console and pairs the certificate with a key it keeps; to use a key from this page on IIS, combine it with the issued certificate into a .pfx file with openssl pkcs12 -export.
  • Only RSA and ECDSA (P-256, P-384) keys are offered: they are what public CAs issue certificates for. Ed25519 keys are not, for that reason.

Privacy

The key pair and the CSR are created by your browser’s Web Crypto API and exist only in this tab: nothing is uploaded, logged or stored. Download what you need before closing the page; Reset removes them from the page.

Frequently asked questions

Is it safe to generate a CSR and private key in a browser?

The key comes from your browser’s Web Crypto API, which uses the operating system’s secure random number generator, and it never leaves this page. If your policy requires the key to be created on the server, run the OpenSSL command shown with the result — it makes the same request there.

Do I need to fill in organisation, city, state and country?

Only for OV and EV certificates, where the CA verifies your organisation. For a domain-validated certificate (such as Let’s Encrypt or most low-cost certificates) the names are all that matter.

Should I add www as well?

Yes: example.com and www.example.com are different names. Put the one you use most as the common name and the other in the list of names; both end up as SANs.

Which file do I send to the certificate authority?

Only the CSR — the text from -----BEGIN CERTIFICATE REQUEST----- to -----END CERTIFICATE REQUEST-----. Never send the private key: the CA does not need it, and anyone who has it can impersonate your site.

Should I protect the private key with a passphrase?

For a key you store or send somewhere, yes. On a web server, nginx and Apache need the passphrase every time they start (typed in, or from a password file), so server keys are usually kept unencrypted and protected by file permissions (chmod 600). The encrypted copy uses AES-256 with PBKDF2; openssl pkey -in example.com.encrypted.key -out example.com.key turns it back into a plain key.

Why would a certificate authority refuse my CSR?

Most often a name in it is one that public CAs cannot certify (an internal name, a private IP address, a name with an underscore — the page flags these), or a CAA record: public CAs must check your domain’s CAA records and may only issue when they are named in an issue record (issuewild for wildcards) (BR §4.2.2.1, RFC 8659). Look them up with the DNS Lookup, record type CAA.

Why does the OpenSSL command for an ECDSA key add -pkeyopt ec_param_enc:named_curve?

So that the key names its curve (P-256 or P-384) instead of spelling out the curve’s parameters. The openssl that comes with macOS is LibreSSL, which spells them out unless told otherwise. RFC 5480 requires the named form and public certificates must use it (BR §7.1.3.1.2), so a CA may refuse such a request. OpenSSL 3 names the curve anyway, so the option changes nothing there. The SSL Certificate Decoder shows which form a CSR’s key uses.

Can I reuse the CSR to renew my certificate?

Many CAs accept the same CSR again, but making a new key and CSR at each renewal is better practice: a key that was ever exposed stops being useful.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.