RSA 2048 is the recommended default — accepted by every CA. RSA 4096 for longer-lived keys, ECDSA P-256 for modern, compact certificates.
(Documentation in English)
What it does
The CSR Generator creates a Certificate Signing Request (PKCS#10) and its matching private key entirely in your browser. Fill in the subject identity (Common Name, Organization, Country, and more), pick a key algorithm — RSA 2048, RSA 4096, or ECDSA P-256 — and it builds the
ASNASNA number identifying one routing domain on the internet (one AS = one network under a single policy), used by BGP to exchange routes.Learn more
.1 DER structure, signs it with the freshly generated key via the Web Crypto API, and hands you a standard PEMCERTIFICATE REQUEST plus the PKCS#8 private key, ready to download and submit to any certificate authority.
Key generation never touches a server: the pair is created locally, the CSR is assembled and signed locally, and the private key is shown only to you. That makes it safe to use for real certificates — no CA, no website, and no middleman ever sees the key.
How to use it
- Enter the Common Name (CN) — the domain the certificate is for, e.g.
www.example.com. This field is required. - Optionally fill Organization, Country (exactly 2 letters, e.g.
US), State / Province, Locality / City, and Email. - Pick a Key algorithm — RSA 2048 (recommended), RSA 4096, or ECDSA P-256.
- Add any Subject Alternative Names (SANs) — extra domains, wildcard names, IPs, emails, or URIs, one per entry.
- Click Generate CSR. RSA 4096 can take a few seconds.
- Copy or download the CSR (
request.csr) and the private key (private.key).
Examples
Simple single-domain CSR
Input: CN www.example.com, algorithm RSA 2048
Output (truncated):
-----BEGIN CERTIFICATE REQUEST-----
MIIClTCCAX0CAQAwHDAaBgNVBAMME3d3dy5leGFtcGxlLmNvbTCBnzANBgkq
...
-----END CERTIFICATE REQUEST-----
Full identity with SANs
Input: CN dev.cosmolabs.org, O CosmoLabs, C US, ST California, L San Francisco,
email gab@cosmolabs.org, SANs cosmolabs.org, 192.168.1.10
Output: a CSR whose subject reads C=US, ST=California, L=San Francisco, O=CosmoLabs, CN=dev.cosmolabs.org, emailAddress=gab@cosmolabs.org with the SANs embedded in an extensionRequest attribute. Verify it anywhere:
openssl req -in request.csr -noout -verify -subject
# Certificate request self-signature verify OK
Validation errors
Input: empty CN → Common Name (CN) is required. Country USA → Country must be a 2-letter ISO 3166-1 code (e.g. US, DE).
Good to know
- Private: everything runs 100% client-side on the Web Crypto API — the private key is generated in your browser and never transmitted anywhere.
- Save your private key securely — it cannot be recovered. It is never uploaded, never re-derived, and once you leave the page it is gone.
- The CSR is emitted as a standard PKCS#10 PEM (
-----BEGIN CERTIFICATE REQUEST-----), signed with SHA-256 (sha256WithRSAEncryptionorecdsa-with-SHA256) — accepted by Let’s Encrypt, DigiCert, and every mainstream CA. - SAN entries are classified automatically: domain names (including wildcards) as dNSName,
http(s)://…as URI,name@domainas email, and IPv4/IPv6 addresses as iPAddress. - Related tools:
JWTJWTA compact, URL-safe token that carries claims (like identity or expiry) between two parties, signed to prevent tampering.Learn more
Decoder,Base64Base64An encoding representing binary data as 64 safe ASCII characters, so it survives transport through text-only channels. It encodes — it does not encrypt.
Encode / Decode, Password Generator.