Free tool
Generate a certificate signing request.
Fill in the details, and your browser generates the keypair and builds the CSR. Hand the CSR to whichever certificate authority you buy from; keep the private key. No account, no cost, nothing to install.
What goes in, and what does not
Two fields decide whether a public CA accepts the request at all.
The hostnames matter, the common name barely does. Browsers have ignored the subject common name since 2017 and read only the subject alternative names, so every name you enter is written into the SAN extension — including the common name. A CSR that names a host only in its subject produces a certificate nothing trusts.
Country must be the two-letter ISO code. ZA, not South Africa. It is a fixed-format field and a CA rejects anything else.
There is no organizational unit field, deliberately. The CA/Browser Forum prohibited OU in publicly-trusted certificates from September 2022. Generators that still offer it produce requests that get rejected, so this one does not.
No challenge password either. It is a legacy PKCS#10 field that no public CA reads.
Need certificates for laptops and phones rather than a web server? That is 802.1X with EAP-TLS, and it works differently — devices enroll themselves over SCEP instead of anyone pasting a CSR.
Your certificate signing request
Your server needs both halves — this key, and the certificate the CA sends back:
ssl_certificate example.com.crt; # what the CA returns
ssl_certificate_key example.com.key; # this key
Apache calls them SSLCertificateFile and SSLCertificateKeyFile; IIS and most appliances want the two combined into a PKCS#12. A certificate authority never needs this file and will never ask for it — anyone who has it can impersonate the certificate you are about to buy.
Certificates for devices, not just servers.
A CSR per host works for a web server. It does not scale to every laptop and phone on your network — those enroll themselves over SCEP, from the MDM you already run, against a certificate authority that is yours alone.
- Your own root and intermediate CA
- Standard SCEP — any MDM, no agent
- Your RADIUS server certificate too, from a CSR