CSR Generator — private key and PKCS#10 request, made locally
CSR Generator
This page creates a key pair inside your browser and signs a PKCS#10 certification
request with it. You get two files at the end: the private key as
-----BEGIN PRIVATE KEY----- (PKCS#8) and the request as
-----BEGIN CERTIFICATE REQUEST-----, plus the raw DER form a CA
portal usually asks for. Fill in the subject fields, add the names the certificate
must cover, press Generate, and hand only the request to your
certificate authority — the key file stays with you.
1. Key
RSA 2048 bit, signed with SHA-256.
RSA 2048 is accepted everywhere and is the safe default. 3072 and 4096 cost more
time to generate — on a slow machine RSA 4096 can take a few seconds, and this
page shows the elapsed time and lets you walk away from the result.
2. Subject
Fields you leave empty are left out of the request entirely. CN is limited to 64
characters, and commercial CAs increasingly ignore it anyway — what they and
the browsers check is the subject alternative names below.
3. Subject alternative names
One entry per line. A line without a prefix is treated as a DNS name, so
www.example.com and dns:www.example.com mean the same
thing; an address literal such as 192.0.2.10 is taken as an IP
address even without the prefix. Prefixes dns:, ip:, email: and
uri: are recognised. A wildcard is allowed only as the leftmost label
(*.example.com), because browsers ignore it anywhere else.
4. Generate
nothing generated yet
Generating…
Result
Nothing generated yet. Fill in at least a common name, press
Generate key and request, and the private key and the request
appear here with buttons to save them.
Use this pair for testing, internal services and learning.
A key generated in a web page is only as safe as the machine it runs on, and the
private key you download is unencrypted: anyone who opens that file has your key.
For a certificate that the public internet must trust, let your certificate authority
or your own server generate the key, and keep it somewhere it cannot be copied.
What a CSR is: a PKCS#10 request holds your public key, the name
fields you typed and the names the certificate should cover, and the whole thing is
signed with your private key. The signature is what proves the request was not altered
on the way to the CA. Your private key is not part of the request and cannot be
recovered from it.
What this page does not do: it does not contact a CA, does not
register anything, and cannot tell you whether your CA will accept these fields —
every CA adds its own rules on top. It also does not encrypt the key file; if you need
that, wrap the key in PKCS#8 encryption or a PKCS#12 container with your own tools.
Privacy: the key pair is generated by the browser's own cryptography
and the request is signed here. No upload, no server, no cookies, no analytics —
the page works from a local file just as well. When you decode the result, the
certificate decoder reads it back without any
network access either.
Then what: paste the request into your CA's order form, or sign it
yourself on the self-signed certificate
generator to see the whole path from key to certificate.
🔒 SSL & TLS Tools
Certificate and key utilities that run entirely in your browser.