CSR

CSR generator

A certificate request and the private key for it. Your browser does the work — we see neither.

This page sends nothing anywhere: the key, the request and the password are computed by your browser and stay in the tab. Close the tab and no trace of them is left — not with us, not on the wire.

Request details

No https:// and no path. This name becomes the primary one in the certificate.

The certificate will cover both kava.com.ua and www.kava.com.ua. Clear it if you do not use www, or if the name is already a subdomain.

The request will cover *.domain and the domain itself. Wildcards are issued only after your control over the zone is verified.

RSA 2048 suits any server. ECDSA puts less load on it, but very old clients do not know it.

Needed only for OV and EV. For an ordinary certificate leave it empty — the authority does not read this field anyway.

Optional. It goes into the request itself and becomes visible to anyone who opens it.

RSA 4096 can take a few seconds — that is normal, the tab has not frozen.

What to do next

  1. Keep the key to yourself

    A password manager or the server’s own store. Not email, not a messenger, not a shared folder.

  2. Give the CSR to the certificate authority

    The order form takes the request — the whole text, BEGIN and END lines included.

  3. Put the certificate next to the key

    The server reads both files. Before restarting it, check that the two are a pair.

Most of the time a CSR is not needed at all

If the domain is served here, the certificate is issued and renewed on its own: no requests, no keys, no copying files around. A CSR is for the cases where the server or the certificate authority is somebody else’s.

Common questions

Where does the private key end up?

In the tab and nowhere else. The page makes no network request at all — open the developer tools, Network tab, and see for yourself. Close the tab and the key is gone, which is why you should save it straight away.

I lost the key and the certificate is already issued

A certificate without its key does not work. You need a new request and a reissued certificate — most authorities reissue free of charge within the original term.

Why is only the domain required?

For a domain-validated certificate the authority checks only your right to the name. City, department and country are ignored — requiring them would mean asking for data that serves no purpose.

RSA or ECDSA?

RSA 2048 when compatibility with old software matters. ECDSA P-256 gives the same margin of strength with a smaller key and a faster handshake; every browser released after 2010 understands it.