Sign a Public Key with a CA

Create a local test certificate from a PEM public key plus a matching CA certificate/private key, with subject and DNS/IP SAN controls.

Privacy: all processing happens locally in your browser. Your input never leaves your device.

What is Sign a Public Key with a CA?

A system may have a public key but no usable CSR, for example in offline configuration or test-device integration. This tool combines that PEM public key with a matching CA certificate/private key and an explicit subject plus DNS/IP SANs to make an X.509 certificate locally. Unlike a CSR, a naked public key provides no proof that the target owns its private key, so the issuer must confirm key ownership and name authorization through a separate process.

How to Use

  1. Import the CA certificate, its matching private key and the target PEM public key
  2. Enter subject, DNS/IP SANs and the minimum necessary validity; HTTPS server purpose is fixed
  3. Confirm the CA key match, issue, export and test the certificate in its target system

FAQ

How is this different from signing a CSR?
A CSR carries a signature from the target private key. Direct public-key signing has no such proof, so ownership must be checked externally.
Can I issue to an IP address?
Yes, but the address must be encoded as an IP SAN, not only in Common Name or as a DNS SAN.
Why are both CA certificate and private key needed?
The private key signs the new certificate; the CA certificate supplies the issuer identity and public key that verifies it.

Related Tools

Last updated 2026-10-09