Skip to main content
SSL/TLS Tools

CSR Generator

Generate Certificate Signing Requests and RSA key pairs in your browser

Keys generated entirely in your browser — nothing is sent to any server
Certificate Details

The fully qualified domain name for your certificate

2-letter ISO country code

Key Size
About CSR Generation

What Is a Certificate Signing Request (CSR)?

A Certificate Signing Request (CSR) is a specially formatted encrypted message sent from an applicant to a Certificate Authority (CA) to apply for an SSL/TLS certificate. The CSR contains the public key that will be included in the certificate, along with identifying information such as the domain name, organization, and location. When you submit a CSR to a CA like Let's Encrypt, DigiCert, or Sectigo, they verify your identity and issue a signed certificate that browsers trust.

Why Do You Need a CSR?

Every SSL/TLS certificate starts with a CSR. Whether you are securing a website with HTTPS, setting up email encryption, or configuring a VPN, the CSR proves you control the private key without ever revealing it. This tool generates both the CSR and the corresponding RSA private key entirely in your browser using the node-forge cryptographic library. No data leaves your device, making it ideal for generating CSRs for production environments where security is paramount.

How This Tool Works

When you click "Generate," the tool creates an RSA key pair (2048 or 4096 bits) using client-side JavaScript. It then constructs a PKCS#10 certification request with your provided subject fields, signs it with SHA-256, and outputs both the CSR and private key in PEM format. You can then submit the CSR to any Certificate Authority and use the private key to install the issued certificate on your server.

Expert guide · CSR Generator

Technical background

Generating a CSR is two operations. First an asymmetric key pair is created; for RSA that means finding two large random primes whose product is the modulus. Second, the public half is placed in a PKCS#10 CertificationRequestInfo (RFC 2986) together with the subject name and optional extensions, and the structure is signed with the private half. The CA verifies that signature, validates domain control (and, for OV/EV, the organization), and then issues an X.509 certificate (RFC 5280) that binds your public key to the validated names. The private key never needs to leave the machine where it was created, which is the whole point of the CSR workflow.

This tool performs both steps with node-forge in JavaScript. Randomness comes from the browser, which seeds forge from the operating system CSPRNG through crypto.getRandomValues, and prime search is offloaded to Web Workers so the page stays responsive. The resulting request uses sha256WithRSAEncryption. The private key is serialized as PKCS#1 (RFC 8017) without a passphrase; if your server expects PKCS#8 (BEGIN PRIVATE KEY) or an encrypted key, convert it with openssl pkey or the SSL Converter.

Two limitations are worth knowing. The generator only builds RSA keys, while the CA/B Forum Baseline Requirements also permit ECDSA on P-256 and P-384, which produce smaller certificates and faster handshakes; use OpenSSL if you want an EC key. It also does not write a subjectAltName extension. Browsers have ignored the Common Name for hostname validation since 2017 and the Baseline Requirements require every name to appear in the SAN extension, so for a single-name order the CA will populate the SAN from your CN, but multi-domain or wildcard-plus-apex orders should be generated with openssl req -addext or entered in the CA order form.

Manual CSR generation is becoming the exception. CA/B Forum ballot SC-081 approved a maximum TLS certificate validity of 200 days from 15 March 2026, 100 days from 15 March 2027 and 47 days from 15 March 2029, so most production endpoints should rely on an ACME client that creates a fresh key and CSR on every renewal. Looking further out, NIST has standardized ML-DSA (FIPS 204) for post-quantum signatures; it is not yet usable for publicly trusted web certificates, but crypto-agile automation will make the eventual switch painless.

Common errors and how to fix them

Problem The issued certificate covers example.com but not www.example.com.
Fix This generator does not write SANs, and not every CA adds www automatically. Either list the extra name in the CA order form or regenerate with openssl req -addext 'subjectAltName=DNS:example.com,DNS:www.example.com'.
Problem The certificate arrived but the private key is gone.
Fix The key exists only in the page until you download or copy it. If it was lost, generate a new key and CSR and ask the CA for a free reissue; a certificate without its key is unusable.
Problem Server refuses the key with an unsupported format or expecting BEGIN PRIVATE KEY.
Fix The tool outputs PKCS#1 (BEGIN RSA PRIVATE KEY). Convert to PKCS#8 with openssl pkey -in private.key -out private.pk8.pem, or use the SSL Converter.
Problem Browser freezes while generating a 4096-bit key.
Fix Prime generation for 4096 bits in JavaScript can take tens of seconds on slow devices. Wait for it to finish, or choose 2048, which every CA accepts and is adequate for short-lived certificates.
Problem CA rejects the CSR because of the Country field.
Fix Use the two-letter ISO 3166-1 alpha-2 code (GB, not UK; US, not USA) and leave it blank for DV orders if you are unsure.

Do it from the command line

macOS

# RSA 2048 key + CSR with SANs (Homebrew OpenSSL 3 recommended over the system LibreSSL)
openssl req -new -newkey rsa:2048 -nodes -keyout example.key -out example.csr -subj '/CN=example.com' -addext 'subjectAltName=DNS:example.com,DNS:www.example.com'
# ECDSA P-256 alternative
openssl req -new -newkey ec -pkeyopt ec_paramgen_curve:P-256 -nodes -keyout ec.key -out ec.csr -subj '/CN=example.com' -addext 'subjectAltName=DNS:example.com'

Windows

# Build request.inf with Subject, KeyLength and a [Extensions] SAN section, then:
certreq -new request.inf request.csr
# After the CA returns the certificate, bind it to the stored key
certreq -accept issued.cer

Linux

# RSA 3072 key + CSR with two SANs
openssl req -new -newkey rsa:3072 -nodes -keyout example.key -out example.csr -subj '/CN=example.com' -addext 'subjectAltName=DNS:example.com,DNS:www.example.com'
# Lock down the key file
chmod 600 example.key

Frequently asked questions

Is it safe to generate a private key in a web browser?

It is safe when the generation is genuinely local, as it is here: node-forge runs in your browser, randomness comes from the operating system through crypto.getRandomValues, and no request carries the key off your device. You can confirm this in the browser Network tab. The remaining risk is your own handling of the downloaded key file.

Should I choose 2048 or 4096 bits?

2048-bit RSA is the minimum accepted by public CAs and is considered adequate well beyond the lifetime of today's short certificates. 4096 bits makes every TLS handshake more expensive for the server and takes longer to generate. If you need more margin, 3072-bit RSA or ECDSA P-256 via OpenSSL are better choices.

Do I need to fill in Organization and Locality for a DV certificate?

No. Domain-validated certificates only prove control of the domain, so CAs strip or ignore organization, unit and location fields. Those fields matter for OV and EV certificates, where the CA checks them against business registries and they appear in the certificate subject.

How do I add multiple domains to my CSR?

Multiple names belong in the Subject Alternative Name extension. This generator writes only the Common Name, so either enter the additional names in your CA order form, which most multi-domain products support, or create the request with OpenSSL using -addext 'subjectAltName=DNS:a.com,DNS:b.com'.

Will I still need CSRs when certificates last 47 days?

Yes, but you will rarely create them by hand. ACME clients generate a key and CSR automatically on every renewal. The SC-081 schedule moving to 200, 100 and finally 47 days makes manual generation impractical for public websites, though it remains useful for internal CAs, appliances and one-off OV orders.

100-Day Max Lifespan
155d 5h 19m 17s
PQC Migration Target
1178d 5h 19m 17s