Search 100+ free tools… (e.g. json, vpn, password) ⌘K
Link Tools Dereferer Hide Referrer Link URL Shortener Affiliate Cloaker PayPal Links PayPal DonationPayPal Links Privacy Tools Password Generator Cloudflare Resolver My Referrer Torrent Tools Magnet → Torrent Torrent → Magnet Torrent Editor Pirate Bay Proxies Movierulz Proxies ExtraTorrent Proxies Dev Tools Base64 Encoder Hash Generator HTTP Headers Disposable Email Checker Company Blog About Us Contact Anonymize Free
SSL Tool

CSR Generator

Generate a Certificate Signing Request (CSR) and private key instantly. Fill in your domain details, download both files and submit the CSR to your Certificate Authority.

⚙️ Certificate Details

Frequently Asked Questions

What information do I need to generate a CSR?
To generate a CSR you need the domain name (Common Name) the certificate will cover, your organisation and organisational unit, country, state or province, city and a contact email. Optional Subject Alternative Names let one CSR cover additional domains.
What key size should I use?
2048-bit RSA is the current minimum. 4096-bit provides stronger security. EC keys at 256-bit are also an excellent choice.
Why are SAN entries important?
Modern browsers require Subject Alternative Names. Without SANs certificates cause errors in Chrome and Firefox even if the CN matches.
What do I do with the generated CSR?
Submit the CSR text (starting with -----BEGIN CERTIFICATE REQUEST-----) to your Certificate Authority (CA) such as Lets Encrypt, DigiCert, Comodo or ZeroSSL. The CA will verify your domain and issue an SSL certificate.
Is the private key generated securely?
The private key is generated server-side using PHP's OpenSSL extension. It is never logged or stored. For maximum security, generate your CSR locally using the OpenSSL command: openssl req -new -newkey rsa:2048 -nodes -keyout private.key -out request.csr
What is the difference between 2048 and 4096 bit keys?
2048-bit keys are the current standard and are considered secure. 4096-bit keys are stronger but slower for TLS handshakes and use more CPU. For most websites, 2048-bit is sufficient. High-security applications may prefer 4096-bit.
🛡️
Your IP address and DNS queries are visible to your ISP. Protect your privacy with a trusted VPN — tested and recommended by Anonymiz.
See Recommended VPNs →

What a CSR is

A Certificate Signing Request is the file you send to a certificate authority to get an SSL/TLS certificate. It holds your public key and the details that will appear in the certificate, mainly the domain names, and it is signed with your private key to prove you hold it. The private key itself is never sent to the authority.

Filling in the fields

Protect the private key

Save the private key as soon as it is generated and store it where only your server administrators can read it. If it is lost, the certificate is useless and must be reissued. If it leaks, anyone can impersonate your site until the certificate is revoked. Never email it or paste it into a support ticket. For production servers, generating the key directly on the server, for example with OpenSSL, means it never exists anywhere else.

Next steps

Check the request with the CSR decoder before you submit it. When the certificate arrives, confirm it pairs with your key using the certificate key matcher, then verify the live site with the SSL checker.

Related articles

Related Tools

🔒
SSL Certificate Check
Check SSL certificate validity
🔍
CSR Decoder
Decode a certificate signing request
🔄
SSL Converter
Convert SSL certificate formats
🗝️
Certificate Key Match
Check SSL cert matches private key
📜
SSL Cert Generator
Generate self-signed SSL certificates
📋
JSON Formatter
Format and validate JSON
Done!