Free tool

Generate a certificate signing request.

Fill in the details, and your browser generates the keypair and builds the CSR. Hand the CSR to whichever certificate authority you buy from; keep the private key. No account, no cost, nothing to install.

Your private key is never sent to us. The keypair is generated by your own browser using the Web Crypto API, and this page makes no network request while it works — you can watch it in your developer tools, or load the page and disconnect first. That also means we cannot recover it. Save the key somewhere safe before you close the tab: without it, the certificate you get back is useless and has to be reissued.

The main hostname the certificate is for. A wildcard such as *.example.com is fine.

One per line. The common name is added automatically — you do not need to repeat it. IPv4 addresses are accepted and encoded as IP SANs.

Needed for an OV or EV certificate, and the legal name is checked against a registry. Leave it blank for a domain-validated certificate.

What goes in, and what does not

Two fields decide whether a public CA accepts the request at all.

The hostnames matter, the common name barely does. Browsers have ignored the subject common name since 2017 and read only the subject alternative names, so every name you enter is written into the SAN extension — including the common name. A CSR that names a host only in its subject produces a certificate nothing trusts.

Country must be the two-letter ISO code. ZA, not South Africa. It is a fixed-format field and a CA rejects anything else.

There is no organizational unit field, deliberately. The CA/Browser Forum prohibited OU in publicly-trusted certificates from September 2022. Generators that still offer it produce requests that get rejected, so this one does not.

No challenge password either. It is a legacy PKCS#10 field that no public CA reads.

Need certificates for laptops and phones rather than a web server? That is 802.1X with EAP-TLS, and it works differently — devices enroll themselves over SCEP instead of anyone pasting a CSR.

Certificates for devices, not just servers.

A CSR per host works for a web server. It does not scale to every laptop and phone on your network — those enroll themselves over SCEP, from the MDM you already run, against a certificate authority that is yours alone.

  • Your own root and intermediate CA
  • Standard SCEP — any MDM, no agent
  • Your RADIUS server certificate too, from a CSR