CSR
CSR generator
A certificate request and the private key for it. Your browser does the work — we see neither.
This page sends nothing anywhere: the key, the request and the password are computed by your browser and stay in the tab. Close the tab and no trace of them is left — not with us, not on the wire.
Request details
What to do next
- Keep the key to yourself
A password manager or the server’s own store. Not email, not a messenger, not a shared folder.
- Give the CSR to the certificate authority
The order form takes the request — the whole text, BEGIN and END lines included.
- Put the certificate next to the key
The server reads both files. Before restarting it, check that the two are a pair.
Most of the time a CSR is not needed at all
If the domain is served here, the certificate is issued and renewed on its own: no requests, no keys, no copying files around. A CSR is for the cases where the server or the certificate authority is somebody else’s.
Common questions
Where does the private key end up?
In the tab and nowhere else. The page makes no network request at all — open the developer tools, Network tab, and see for yourself. Close the tab and the key is gone, which is why you should save it straight away.
I lost the key and the certificate is already issued
A certificate without its key does not work. You need a new request and a reissued certificate — most authorities reissue free of charge within the original term.
Why is only the domain required?
For a domain-validated certificate the authority checks only your right to the name. City, department and country are ignored — requiring them would mean asking for data that serves no purpose.
RSA or ECDSA?
RSA 2048 when compatibility with old software matters. ECDSA P-256 gives the same margin of strength with a smaller key and a faster handshake; every browser released after 2010 understands it.