CSR Generator
Create a local CSR and private key with DNS/IP SANs using RSA, ECC P-256/P-384 or SM2.
Privacy: all processing happens locally in your browser. Your input never leaves your device.
What is CSR Generator?
A Certificate Signing Request contains the applicant public key and subject information, then is signed by its matching private key for a CA. Modern clients chiefly match names against Subject Alternative Names: hostnames belong in DNS SAN entries and IP addresses belong in IP SAN entries. By default this tool creates a local RSA 2048/3072/4096, ECC P-256/P-384 or SM2 key and CSR. You can instead select an existing private key to create a CSR with that key. Submit only the CSR to a trusted CA; the private key must never leave the applicant's control.
How to Use
- Choose a new private key or an existing one; select the new key algorithm or import an existing PEM key
- Fill the subject and DNS/IP SANs; optionally protect a new key or enter the existing encrypted key password
- Download the CSR and keep any newly generated private key; submit only the CSR to your CA
FAQ
- Can I generate a CSR without a private key?
- Yes. Generate a new private key is selected by default and creates the CSR and key pair locally. Switch to an existing key to reuse it; that mode requires the key and will not silently create a replacement.
- Does a CSR contain the private key?
- No, and it must not. A CSR contains a public key and a signature; the private key stays with the requester.
- Can Common Name replace SAN?
- No. Modern clients expect the target DNS name or IP address in SAN. Common Name is mainly retained for display and compatibility.
- How does a wildcard work?
- A DNS SAN such as *.example.com normally does not cover example.com itself or deeper labels. Confirm the exact CA rules.
Related Tools
Last updated 2026-10-09