CSR Generator

This page creates a key pair inside your browser and signs a PKCS#10 certification request with it. You get two files at the end: the private key as -----BEGIN PRIVATE KEY----- (PKCS#8) and the request as -----BEGIN CERTIFICATE REQUEST-----, plus the raw DER form a CA portal usually asks for. Fill in the subject fields, add the names the certificate must cover, press Generate, and hand only the request to your certificate authority — the key file stays with you.
1. Key
RSA 2048 bit, signed with SHA-256.
RSA 2048 is accepted everywhere and is the safe default. 3072 and 4096 cost more time to generate — on a slow machine RSA 4096 can take a few seconds, and this page shows the elapsed time and lets you walk away from the result.
2. Subject
Fields you leave empty are left out of the request entirely. CN is limited to 64 characters, and commercial CAs increasingly ignore it anyway — what they and the browsers check is the subject alternative names below.
3. Subject alternative names
One entry per line. A line without a prefix is treated as a DNS name, so www.example.com and dns:www.example.com mean the same thing; an address literal such as 192.0.2.10 is taken as an IP address even without the prefix. Prefixes dns:, ip:, email: and uri: are recognised. A wildcard is allowed only as the leftmost label (*.example.com), because browsers ignore it anywhere else.
4. Generate
nothing generated yet
Nothing generated yet. Fill in at least a common name, press Generate key and request, and the private key and the request appear here with buttons to save them.
Use this pair for testing, internal services and learning. A key generated in a web page is only as safe as the machine it runs on, and the private key you download is unencrypted: anyone who opens that file has your key. For a certificate that the public internet must trust, let your certificate authority or your own server generate the key, and keep it somewhere it cannot be copied.
What a CSR is: a PKCS#10 request holds your public key, the name fields you typed and the names the certificate should cover, and the whole thing is signed with your private key. The signature is what proves the request was not altered on the way to the CA. Your private key is not part of the request and cannot be recovered from it.

What this page does not do: it does not contact a CA, does not register anything, and cannot tell you whether your CA will accept these fields — every CA adds its own rules on top. It also does not encrypt the key file; if you need that, wrap the key in PKCS#8 encryption or a PKCS#12 container with your own tools.

Privacy: the key pair is generated by the browser's own cryptography and the request is signed here. No upload, no server, no cookies, no analytics — the page works from a local file just as well. When you decode the result, the certificate decoder reads it back without any network access either.

Then what: paste the request into your CA's order form, or sign it yourself on the self-signed certificate generator to see the whole path from key to certificate.