Settings
Result appears here after you select
{ } How to use
- Enter the domain the certificate is for. Add any other domains it should cover in the options.
- Choose a key type, and fill in whichever organisation details your certificate authority asks for.
- Select Process, then save both blocks: send the CERTIFICATE REQUEST to your authority and keep the PRIVATE KEY.
{ } How it works
CSR Generator works on the text you provide. Adjust the options, then select Process ▸ and it runs entirely in your browser — nothing is uploaded to a server — then shows the result in the Output panel.
Inputs
- Domain (common name) — paste or type your input in the left panel (use Sample for an example)
- Key type — choose one — RSA 2048 — widest compatibility, RSA 4096 — stronger, slower, ECDSA P-256 — modern, fast, ECDSA P-384 — modern, stronger (default: RSA 2048 — widest compatibility)
- Other domains (comma separated) — a value
- Organisation — a value
- Organisational unit — a value
- City — a value
- State or province — a value
- Country code (2 letters) — a value
- Email address — a value
Output
TXT text — copy or download it from the Output panel.
{ } Common uses
- Order a certificate without installing OpenSSL or working out its command line.
- Create a request covering several domains at once with subject alternative names.
- Generate a fresh key and request on a machine that has no certificate tooling.
- Produce a request for a wildcard certificate such as *.example.com.
{ } Limitations
- The private key is shown once and stored nowhere. If you lose it, the certificate issued from this request cannot be used and you will have to start again.
- The key is generated by the browser’s own cryptography, which needs a secure connection; over plain HTTP the browser refuses and the tool says so rather than falling back to something weaker.
- Some certificate authorities require particular subject fields, or ignore them entirely and use only the domains. Check what yours asks for before you order.
{ } Troubleshooting
My certificate authority rejected the request.
Decode it with the CSR Decoder first and compare the names and key size against what the authority asked for. The most common causes are a missing organisation field where one is required, and a key smaller than the authority’s minimum.
I closed the page before saving the private key.
Generate a new request. The key existed only in that tab and is genuinely gone — there is no copy here to recover, which is the same property that makes it safe to generate one on a web page.
{ } FAQ
Is my data uploaded to a server?
No. Everything runs locally in your browser — your files never leave your device.
Can I process more than one file at once?
This tool works on one input at a time.
Is this tool free?
Yes — it’s completely free and needs no sign-up.
Is a key generated in a browser safe to use?
Yes. It comes from the browser’s built-in cryptography — the same implementation that secures your HTTPS connections, seeded by the operating system — rather than from arithmetic written in JavaScript. It is created in this tab, used to sign the request, and never sent anywhere.
Why is my domain listed twice?
The domain you enter is repeated as a subject alternative name because browsers stopped honouring the common name years ago and match on the alternative names alone. A request without it produces a certificate browsers would reject.
Is my private key uploaded anywhere?
No. Every one of these tools runs entirely in your browser — the certificate and key are read, converted and shown without a byte being sent anywhere. That is what makes it safe to paste a private key, which you should never do on a site that converts it on a server.
Does this work with ECDSA certificates?
Yes. RSA, ECDSA and Ed25519 are all read the same way, because the structure is read directly rather than through a library that only understands RSA keys.