Issue a Certificate with an Existing CA

Generate a leaf private key and DNS/IP SAN certificate locally, signed by a user-provided matching CA certificate and private key; no CA or chain is created.

Privacy: all processing happens locally in your browser. Your input never leaves your device.

What is Issue a Certificate with an Existing CA?

When an internal CA already exists, this tool removes repetitive steps of generating a leaf key and issuing its leaf certificate. It creates a leaf private key locally, then uses the user-provided, matching CA certificate and CA private key to sign a leaf certificate with DNS/IP SANs. It does not create a new CA and does not create or complete a certificate chain; trust distribution, chain configuration, rotation, revocation and audit remain the responsibility of your PKI process.

How to Use

  1. Import an existing CA certificate and its matching CA private key
  2. Enter the leaf subject and DNS/IP SANs, then choose a leaf-key algorithm
  3. Generate the leaf private key and CA-signed leaf certificate; configure chains separately through the existing PKI process

FAQ

Does this tool create a new CA?
No. You must provide an existing CA certificate and the private key that matches it.
Does it generate a certificate chain automatically?
No. It produces only a leaf key and a leaf certificate signed by the supplied CA; intermediate chains and trust roots follow your existing deployment process.
What happens if the CA certificate and key do not match?
Issuance should be rejected. Use the private key whose public key matches the supplied CA certificate, then issue again.

Related Tools

Last updated 2026-10-09