Certificate Generator
Generate self-signed Root CA, TLS server, and TLS client certificates with RSA or EC keys, proper usage extensions, and downloadable PEM files.
Certificate settings
Certificate generation
Generate certificates locally
Create certificates for development, testing, and internal PKI without uploading private keys.
What you can generate
Generate Root CA, TLS server, and TLS client certificates using RSA or Elliptic Curve keys with appropriate extensions.
Intended usage
These certificates are ideal for local development, internal environments, laboratories, and testing. They are not replacements for publicly trusted certificates.
Guide
About Self-Signed Certificate Generator
Self-signed certificates are useful for local development, laboratories, internal services, and private PKI testing.
This tool generates key pairs and X.509 certificates with profiles for Root CAs, TLS servers, and TLS clients.
Generated private keys must be protected, and self-signed certificates are not publicly trusted unless their issuing CA is explicitly installed.
Certificate profiles
Choose a profile that matches the intended role.
- Root CA certificates
- TLS server certificates
- TLS client certificates
- RSA and elliptic-curve keys
Extensions matter
Basic Constraints, Key Usage, Extended Key Usage, and Subject Alternative Names determine how software interprets a certificate.
Development versus production
Self-signed certificates are appropriate for controlled environments. Public production services normally require a certificate from a trusted CA.
Private-key safety
Store generated private keys securely, restrict file permissions, and never publish or transmit them unnecessarily.
FAQ
Frequently asked questions
Are self-signed certificates trusted by browsers?
Not automatically. The issuing certificate must be installed in the relevant trust store.
Can I generate a Root CA?
Yes. The tool supports a self-signed Root CA profile.
Can I generate server and client certificates?
Yes. Separate TLS server and client profiles are available.
Should a server certificate include SAN entries?
Yes. Modern hostname validation relies on Subject Alternative Names.
Which is better, RSA or EC?
Both can be secure when configured correctly. Compatibility and organizational policy usually determine the choice.
Are private keys uploaded?
Generation is intended to occur locally in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
CSR Generator
Generate RSA or EC PKCS#10 certificate signing requests and private keys locally.
PKI & Certificates
X.509 Certificate Decoder
Decode certificate identity, validity, algorithms, key details, and fingerprints locally.
PKI & Certificates
Certificate & Private Key Match Checker
Verify whether an X.509 certificate and RSA private key contain the same public key.
PKI & Certificates
Certificate Chain Builder
Order X.509 certificates and generate fullchain.pem and chain.pem locally.
PKI & Certificates
CSR Decoder
Decode PKCS#10 certificate signing requests and review requested identities, keys, and extensions.
PKI & Certificates
Public & Private Key Analyzer
Identify PEM and OpenSSH key algorithms, formats, sizes, curves, and fingerprints locally.
PKI & Certificates