CSR Generator

Create a local CSR and private key with DNS/IP SANs using RSA, ECC P-256/P-384 or SM2.

Privacy: all processing happens locally in your browser. Your input never leaves your device.

What is CSR Generator?

A Certificate Signing Request contains the applicant public key and subject information, then is signed by its matching private key for a CA. Modern clients chiefly match names against Subject Alternative Names: hostnames belong in DNS SAN entries and IP addresses belong in IP SAN entries. By default this tool creates a local RSA 2048/3072/4096, ECC P-256/P-384 or SM2 key and CSR. You can instead select an existing private key to create a CSR with that key. Submit only the CSR to a trusted CA; the private key must never leave the applicant's control.

How to Use

  1. Choose a new private key or an existing one; select the new key algorithm or import an existing PEM key
  2. Fill the subject and DNS/IP SANs; optionally protect a new key or enter the existing encrypted key password
  3. Download the CSR and keep any newly generated private key; submit only the CSR to your CA

FAQ

Can I generate a CSR without a private key?
Yes. Generate a new private key is selected by default and creates the CSR and key pair locally. Switch to an existing key to reuse it; that mode requires the key and will not silently create a replacement.
Does a CSR contain the private key?
No, and it must not. A CSR contains a public key and a signature; the private key stays with the requester.
Can Common Name replace SAN?
No. Modern clients expect the target DNS name or IP address in SAN. Common Name is mainly retained for display and compatibility.
How does a wildcard work?
A DNS SAN such as *.example.com normally does not cover example.com itself or deeper labels. Confirm the exact CA rules.

Related Tools

Last updated 2026-10-09