Certificate Generator

Generate self-signed Root CA, TLS server, and TLS client certificates with RSA or EC keys, proper usage extensions, and downloadable PEM files.

Browser onlyRSA & ECPEM download

Certificate settings

Certificate generation

Generate certificates locally

Create certificates for development, testing, and internal PKI without uploading private keys.

What you can generate

Generate Root CA, TLS server, and TLS client certificates using RSA or Elliptic Curve keys with appropriate extensions.

Intended usage

These certificates are ideal for local development, internal environments, laboratories, and testing. They are not replacements for publicly trusted certificates.

Guide

About Self-Signed Certificate Generator

Self-signed certificates are useful for local development, laboratories, internal services, and private PKI testing.

This tool generates key pairs and X.509 certificates with profiles for Root CAs, TLS servers, and TLS clients.

Generated private keys must be protected, and self-signed certificates are not publicly trusted unless their issuing CA is explicitly installed.

Certificate profiles

Choose a profile that matches the intended role.

  • Root CA certificates
  • TLS server certificates
  • TLS client certificates
  • RSA and elliptic-curve keys

Extensions matter

Basic Constraints, Key Usage, Extended Key Usage, and Subject Alternative Names determine how software interprets a certificate.

Development versus production

Self-signed certificates are appropriate for controlled environments. Public production services normally require a certificate from a trusted CA.

Private-key safety

Store generated private keys securely, restrict file permissions, and never publish or transmit them unnecessarily.

FAQ

Frequently asked questions

Are self-signed certificates trusted by browsers?

Not automatically. The issuing certificate must be installed in the relevant trust store.

Can I generate a Root CA?

Yes. The tool supports a self-signed Root CA profile.

Can I generate server and client certificates?

Yes. Separate TLS server and client profiles are available.

Should a server certificate include SAN entries?

Yes. Modern hostname validation relies on Subject Alternative Names.

Which is better, RSA or EC?

Both can be secure when configured correctly. Compatibility and organizational policy usually determine the choice.

Are private keys uploaded?

Generation is intended to occur locally in your browser.

Continue exploring

Useful tools for the next step in the same workflow.