Sign a Public Key with a CA
Create a local test certificate from a PEM public key plus a matching CA certificate/private key, with subject and DNS/IP SAN controls.
Privacy: all processing happens locally in your browser. Your input never leaves your device.
What is Sign a Public Key with a CA?
A system may have a public key but no usable CSR, for example in offline configuration or test-device integration. This tool combines that PEM public key with a matching CA certificate/private key and an explicit subject plus DNS/IP SANs to make an X.509 certificate locally. Unlike a CSR, a naked public key provides no proof that the target owns its private key, so the issuer must confirm key ownership and name authorization through a separate process.
How to Use
- Import the CA certificate, its matching private key and the target PEM public key
- Enter subject, DNS/IP SANs and the minimum necessary validity; HTTPS server purpose is fixed
- Confirm the CA key match, issue, export and test the certificate in its target system
FAQ
- How is this different from signing a CSR?
- A CSR carries a signature from the target private key. Direct public-key signing has no such proof, so ownership must be checked externally.
- Can I issue to an IP address?
- Yes, but the address must be encoded as an IP SAN, not only in Common Name or as a DNS SAN.
- Why are both CA certificate and private key needed?
- The private key signs the new certificate; the CA certificate supplies the issuer identity and public key that verifies it.
Related Tools
SSL Key Pair GeneratorGenerate RSA, ECC or SM2 PEM key pairs locally: RSA 2048/3072/4096 and P-256/P-384 are supported.Key Format ConverterConvert RSA PKCS#1 and general PKCS#8 private keys locally, optionally changing output password protection without changing the underlying key.Private Key Parameter ParserInspect public parameters of an RSA, ECC or SM2 private key and export its public key locally, without revealing private mathematical components.Public Key Parameter ParserParse the algorithm, RSA bit length or elliptic-curve parameters of an RSA, ECC or SM2 PEM/DER public key locally.CSR GeneratorCreate a local CSR and private key with DNS/IP SANs using RSA, ECC P-256/P-384 or SM2.CSR Parser & Signature CheckerParse a PEM/DER CSR, show subject, public key and DNS/IP SANs, and verify its embedded signature locally.
Last updated 2026-10-09