CSR Generator

Generate a PKCS#10 certificate signing request and private key locally in your browser.

Browser onlyRSA & ECPKCS#10

Certificate request details

Subject Alternative Names

Add DNS names, IP addresses, or email addresses to the CSR.

Wildcards such as *.example.com are supported for DNS entries.

Certificate enrollment

Generate a certificate signing request locally

A CSR contains the public key and identity information that a certificate authority uses when issuing a certificate.

What this tool creates

Generate RSA or elliptic-curve private keys together with a PKCS#10 certificate signing request containing the requested subject and Subject Alternative Names.

Protect the private key

Keep the generated private key confidential and store it securely. Only the CSR should be submitted to a certificate authority.

Guide

About CSR Generator

A CSR is submitted to a certificate authority when requesting an X.509 certificate.

This generator creates a new private key and a signed PKCS#10 request containing the selected subject and Subject Alternative Names.

Keep the private key secure and submit only the CSR to the certificate authority.

What this tool generates

Create compatible key and request material for common certificate enrollment workflows.

  • RSA or elliptic-curve private key
  • PKCS#10 CSR
  • Subject distinguished name
  • DNS and IP SAN entries
  • PEM output

Subject Alternative Names

Modern TLS certificates should place hostnames and IP addresses in the SAN extension request.

Choose an appropriate key

Select an algorithm and size or curve supported by your CA, clients, servers, and organizational policy.

Protect the private key

The generated key controls the certificate identity and must not be uploaded, emailed, or stored in source control.

FAQ

Frequently asked questions

What should I send to the CA?

Send the CSR, not the private key.

Should I include SAN entries?

Yes. Modern hostname validation uses Subject Alternative Names.

Can I reuse a private key?

It is possible, but generating a new key for renewal can reduce the impact of an older key compromise.

Which key algorithm should I choose?

Choose RSA or EC based on compatibility, policy, and CA support.

Does the CSR determine the final certificate?

Not completely. The CA applies policy and may modify or reject requested values.

Are generated keys uploaded?

Generation is intended to occur locally in your browser.

Continue exploring

Useful tools for the next step in the same workflow.