Self-Signed SSL Certificate Generator
Generate local self-signed TLS certificates with DNS/IP SANs for development, intranets and controlled testing using RSA, ECC or SM2.
Privacy: all processing happens locally in your browser. Your input never leaves your device.
What is Self-Signed SSL Certificate Generator?
A self-signed certificate is signed by its own private key. It is useful for localhost, development, intranets and controlled devices where a private trust root is intentionally managed. Generate DNS/IP SANs and RSA, ECC or SM2 material locally here. Public browsers and operating systems do not trust a self-signed certificate by default, so it will produce warnings. It is not a substitute for a publicly trusted CA certificate on a public website.
How to Use
- Choose a new or existing private key, certificate purpose, validity and subject; enter SANs for HTTPS
- Generate locally and download PEM or DER CER; optionally protect a new private key and also create PFX
- Install or trust it only in controlled environments and test with the exact host name
FAQ
- Can I use an existing private key?
- Yes. Choose an existing private key, paste or import PEM and enter its password if encrypted. Its algorithm is detected and no replacement key is created. Select PFX to package the original key with the new certificate using a separate container password.
- Can I download PFX directly?
- Yes. Select Also create PFX and set an output password of at least eight characters. PEM and DER CER certificate downloads are also available.
- Why does the browser still show a warning?
- The issuer is not a public or enterprise trust anchor in the device trust store. A self-signed issuer is untrusted by default.
- Can it replace a real website certificate?
- No. Public visitors do not pre-trust your root. Obtain a certificate from a publicly trusted CA for public domain names.
- Does a self-signed certificate need SANs?
- Yes. Browser name matching relies on DNS/IP SANs, including for localhost, intranet names and IP testing.
- Does parsing or creating it make it trusted?
- No. Local parsing does not check trust, revocation or a complete chain, and self-signed certificates are not publicly trusted.
Related Tools
SSL Key Pair GeneratorGenerate RSA, ECC or SM2 PEM key pairs locally: RSA 2048/3072/4096 and P-256/P-384 are supported.Key Format ConverterConvert RSA PKCS#1 and general PKCS#8 private keys locally, optionally changing output password protection without changing the underlying key.Private Key Parameter ParserInspect public parameters of an RSA, ECC or SM2 private key and export its public key locally, without revealing private mathematical components.Public Key Parameter ParserParse the algorithm, RSA bit length or elliptic-curve parameters of an RSA, ECC or SM2 PEM/DER public key locally.CSR GeneratorCreate a local CSR and private key with DNS/IP SANs using RSA, ECC P-256/P-384 or SM2.CSR Parser & Signature CheckerParse a PEM/DER CSR, show subject, public key and DNS/IP SANs, and verify its embedded signature locally.
Last updated 2026-10-09