CSR Generator
Generate a PKCS#10 certificate signing request and private key locally in your browser.
Certificate request details
Subject Alternative Names
Add DNS names, IP addresses, or email addresses to the CSR.
Wildcards such as *.example.com are supported for DNS entries.
Certificate enrollment
Generate a certificate signing request locally
A CSR contains the public key and identity information that a certificate authority uses when issuing a certificate.
What this tool creates
Generate RSA or elliptic-curve private keys together with a PKCS#10 certificate signing request containing the requested subject and Subject Alternative Names.
Protect the private key
Keep the generated private key confidential and store it securely. Only the CSR should be submitted to a certificate authority.
Guide
About CSR Generator
A CSR is submitted to a certificate authority when requesting an X.509 certificate.
This generator creates a new private key and a signed PKCS#10 request containing the selected subject and Subject Alternative Names.
Keep the private key secure and submit only the CSR to the certificate authority.
What this tool generates
Create compatible key and request material for common certificate enrollment workflows.
- RSA or elliptic-curve private key
- PKCS#10 CSR
- Subject distinguished name
- DNS and IP SAN entries
- PEM output
Subject Alternative Names
Modern TLS certificates should place hostnames and IP addresses in the SAN extension request.
Choose an appropriate key
Select an algorithm and size or curve supported by your CA, clients, servers, and organizational policy.
Protect the private key
The generated key controls the certificate identity and must not be uploaded, emailed, or stored in source control.
FAQ
Frequently asked questions
What should I send to the CA?
Send the CSR, not the private key.
Should I include SAN entries?
Yes. Modern hostname validation uses Subject Alternative Names.
Can I reuse a private key?
It is possible, but generating a new key for renewal can reduce the impact of an older key compromise.
Which key algorithm should I choose?
Choose RSA or EC based on compatibility, policy, and CA support.
Does the CSR determine the final certificate?
Not completely. The CA applies policy and may modify or reject requested values.
Are generated keys uploaded?
Generation is intended to occur locally in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
CSR Decoder
Decode PKCS#10 certificate signing requests and review requested identities, keys, and extensions.
PKI & Certificates
Certificate Generator
Generate self-signed Root CA, TLS server, and TLS client certificates with RSA or EC keys.
PKI & Certificates
Certificate & Private Key Match Checker
Verify whether an X.509 certificate and RSA private key contain the same public key.
PKI & Certificates
Public & Private Key Analyzer
Identify PEM and OpenSSH key algorithms, formats, sizes, curves, and fingerprints locally.
PKI & Certificates
X.509 Certificate Decoder
Decode certificate identity, validity, algorithms, key details, and fingerprints locally.
PKI & Certificates
PEM / DER Converter
Convert certificates, CSRs, public keys, and private keys between PEM, DER, and Base64.
PKI & Certificates