Issue a Certificate with an Existing CA
Generate a leaf private key and DNS/IP SAN certificate locally, signed by a user-provided matching CA certificate and private key; no CA or chain is created.
Privacy: all processing happens locally in your browser. Your input never leaves your device.
What is Issue a Certificate with an Existing CA?
When an internal CA already exists, this tool removes repetitive steps of generating a leaf key and issuing its leaf certificate. It creates a leaf private key locally, then uses the user-provided, matching CA certificate and CA private key to sign a leaf certificate with DNS/IP SANs. It does not create a new CA and does not create or complete a certificate chain; trust distribution, chain configuration, rotation, revocation and audit remain the responsibility of your PKI process.
How to Use
- Import an existing CA certificate and its matching CA private key
- Enter the leaf subject and DNS/IP SANs, then choose a leaf-key algorithm
- Generate the leaf private key and CA-signed leaf certificate; configure chains separately through the existing PKI process
FAQ
- Does this tool create a new CA?
- No. You must provide an existing CA certificate and the private key that matches it.
- Does it generate a certificate chain automatically?
- No. It produces only a leaf key and a leaf certificate signed by the supplied CA; intermediate chains and trust roots follow your existing deployment process.
- What happens if the CA certificate and key do not match?
- Issuance should be rejected. Use the private key whose public key matches the supplied CA certificate, then issue again.
Related Tools
Last updated 2026-10-09