Sign a CSR with a CA
Use a matching CA certificate and CA private key to sign a verified CSR with DNS/IP SAN extensions locally for internal PKI testing.
Privacy: all processing happens locally in your browser. Your input never leaves your device.
What is Sign a CSR with a CA?
A sound internal-CA flow first verifies the CSR signature, then proves the CA certificate matches the CA private key, and finally issues an approved subject, SANs, usages and validity period. This tool validates the request signature and CA material and uses the CSR’s subject and DNS/IP SANs. It issues a fixed HTTPS server leaf certificate (serverAuth); subject and purpose cannot be overridden here. It is suitable for experiments and governed internal PKI, not a replacement for identity review, revocation, audit, trust-root distribution or protected root-key custody.
How to Use
- Import the CA certificate, matching CA private key and target CSR; enter passwords locally if needed
- Review CSR signature, CA key match and DNS/IP SANs
- Set controlled validity, export the leaf certificate, and configure the chain using your existing CA material
FAQ
- Why must the CA certificate match the CA private key?
- Only the corresponding private key can produce a signature verifiable with that CA certificate's public key.
- Can I issue a CSR whose signature fails?
- You should not. It signals inconsistent or altered request material; obtain or generate a valid CSR first.
- Will devices automatically trust an internal-CA certificate?
- No. The root or intermediate CA must be distributed through controlled device trust management with rotation, revocation and audit.
Related Tools
Last updated 2026-10-09