PKI Guide

How to Decode a CSR Online

A Certificate Signing Request contains the identity and public key information that will be submitted to a Certificate Authority when requesting a certificate.

Open CSR Decoder →

What is a CSR?

CSR stands for Certificate Signing Request. A CSR is normally generated together with a private key before requesting an X.509 certificate from a Certificate Authority.

The CSR contains the corresponding public key plus identity information requested for the certificate.

What does a CSR look like?

-----BEGIN CERTIFICATE REQUEST-----
MIIC...
...request data...
-----END CERTIFICATE REQUEST-----

Some software may use the label BEGIN NEW CERTIFICATE REQUEST instead.

How to decode a CSR

  1. 1. Copy the complete PEM encoded CSR.
  2. 2. Open the CSR Decoder.
  3. 3. Paste the request.
  4. 4. Decode it.
  5. 5. Review the subject, SANs, public key, signature, and extensions before submitting it to a CA.

Important CSR fields to inspect

Subject

The subject may contain identity information such as Common Name, organization, organizational unit, locality, and country.

Subject Alternative Names

SAN entries identify DNS names or other identities requested for the resulting certificate.

Public key

The CSR contains the public key that the requested certificate will bind to the identity.

Signature algorithm

The CSR is signed using the corresponding private key. This helps prove possession of that key.

Requested extensions

A CSR may contain requested X.509 extensions such as Subject Alternative Name.

CSR vs. certificate

A CSR is a request for a certificate. It is not itself a trusted certificate.

After validating the request, a Certificate Authority may issue an X.509 certificate based on the CSR.

To inspect the resulting certificate, use the Certificate Decoder.

Can you decode a CSR with OpenSSL?

Yes. For a PEM CSR:

openssl req -in request.csr -text -noout

Does a CSR contain the private key?

No. A correctly generated CSR contains the public key, not the private key.

Never send your private key with the CSR.

The private key should remain under the control of the system or person that generated the request.

Related tools

Decode a CSR now

Inspect a PKCS#10 Certificate Signing Request before sending it to your Certificate Authority.

Open CSR Decoder →