CSR Generator

Securely generate your Certificate Signing Request and Private Key.

Fully Qualified Domain Name
Email address to be associated with the certificate
Encryption Strength

Higher bit value means better security.

CSR Output
Private KeySECRET

Secure Generation

Cryptographic operations are performed server-side. Your keys are generated securely. They are never stored!

Instant Result

Get your CSR and Private Key files in seconds.

Industry Standard

Supports 2048-bit and 4096-bit RSA keys compatible with all major CAs.

What is a CSR?

A CSR (Certificate Signing Request) is the request sent to a certificate authority to get an SSL certificate. It contains your domain name, organization details and public key. The private key created together with the CSR stays on your server and is used together with the certificate.

The tool creates a 2048 or 4096-bit RSA key pair and its CSR on our server. Both are sent only to you over an encrypted connection; they are not stored or written to any log. You can download them as .csr and .key files or copy them.

How to use

  1. 1Enter the domain the certificate is for in the Common Name field (for example www.example.com, or *.example.com for a wildcard certificate).
  2. 2Fill in the organization, unit, city, state, country and email fields and choose the key size.
  3. 3Press Generate CSR; send the CSR to your certificate provider and keep the private key somewhere safe.

Frequently asked questions

What happens if I lose my private key?

A certificate only works with the private key created together with it. If the key is lost, you need to create a new CSR and key and have the certificate reissued through your provider; most providers do this for free.

Should I choose 2048 or 4096 bits?

2048-bit RSA is the standard accepted by all certificate authorities and considered secure today; it is also faster. 4096 bits offers longer-term security but puts slightly more load on the server during connection setup. Unless you have a specific requirement, 2048 bits is enough.

How do I enter the Common Name for a wildcard certificate?

Put an asterisk in front of the domain: *.example.com. Such a certificate covers single-level subdomains such as www.example.com and mail.example.com, but not deeper levels such as a.b.example.com. Most providers add example.com itself to the certificate automatically.

How can I check the contents of a CSR?

Run openssl req -in domain.csr -noout -text with OpenSSL to see the details in the CSR. Once you have confirmed the domain and organization details are correct, send the CSR to your certificate provider.

What should I enter as the country?

The country field takes a two-letter ISO code, for example TR for Turkey or US for the United States. Filling in the other fields exactly as in your organization's official records speeds up validation for organization-validated (OV and EV) certificates.