SSL Key Pair Generator

Generate RSA, ECC or SM2 PEM key pairs locally: RSA 2048/3072/4096 and P-256/P-384 are supported.

Privacy: all processing happens locally in your browser. Your input never leaves your device.

What is SSL Key Pair Generator?

A TLS certificate needs a matching public/private key pair: the private key proves control while the public key is embedded in a CSR or certificate. Generate RSA 2048, 3072 or 4096-bit keys, ECC P-256/P-384 keys, or SM2 keys locally in the browser. RSA has broad compatibility; ECC is usually smaller and faster. SM2 is an algorithm in the Chinese commercial cryptography ecosystem, but selecting SM2 alone does not create a dual-certificate TLCP deployment. Protect production private keys with encryption and access controls.

How to Use

  1. Choose RSA, ECC or SM2 and its size or curve
  2. Optionally set a private-key passphrase, then generate locally in a Worker
  3. Download the PEM private and public keys; keep the private key in a controlled system

FAQ

Which RSA size should I choose?
RSA 2048 is broadly compatible for Web TLS. Choose 3072 or 4096 only when your lifecycle or policy calls for it, as handshake cost grows.
P-256 or P-384?
P-256 is the usual compatibility and performance choice; P-384 offers a higher security margin. Confirm support across clients, load balancers and your CA.
Does SM2 mean dual-certificate TLCP?
No. TLCP dual-certificate deployment also requires signing/encryption certificates, supported protocol stacks, cipher suites and server configuration.
Are my keys or passphrases uploaded?
No. Key material and passwords are processed only in the current browser Worker, with no history, cloud sync or upload to this site.

Related Tools

Last updated 2026-10-09