Tools › Security
Certificate Maker
Make a certificate signing request (CSR) to send to a certificate authority, and a self-signed certificate for testing, with a new private key or one you already have. Host names, IP addresses and email addresses go in as alternative names.
About this tool What it's for, how to use it and an example
What it's for
Make what you need to get a TLS (SSL) certificate: a certificate signing request (CSR) to send to a certificate authority, and a private key to go with it. A self-signed certificate is made at the same time, for testing and internal servers.
For example, when your hosting company asks for a CSR for www.example.com and example.com, make it here, send
them the request and install the private key on your server.
How to use it
Fill in the names: the common name (CN) is usually the main host name, and the organisation, place and country (two
letters, such as GB) are what the certificate says about you. Put every host name, IP address or email address
the certificate should cover under Alternative names, one a line; browsers only look at these. Choose a key type
and press Make.
You get the request (.csr), a self-signed certificate (.crt, valid for the days you set) and the private key
(.key, PKCS #8 PEM), each with Copy and Save. To renew with the key you already have, paste it under
Use a private key you already have and choose its type; no new key is made. Open any of the results in the
Certificate Decoder to check them.
Example
Type www.example.com as the common name and GB as the country, put www.example.com and example.com under
Alternative names, choose ECDSA P-256 and press Make.
The message says Made a request and a self-signed certificate, valid for 365 days. The request starts
-----BEGIN CERTIFICATE REQUEST-----, and the Certificate Decoder shows both names in it.
Good to know
A self-signed certificate isn’t trusted by browsers, so they warn about it; it’s for testing, or for systems you tell to trust it. The self-signed certificate is for servers and clients (not a certificate authority). The private key is shown only until you leave the page and is never stored: save it, and treat it like a password.
Use a private key you already have
Check either in the Certificate Decoder.
Private: this tool runs in your browser. Nothing you type, paste or choose leaves this page.
Saved you a few minutes? Say thanks with a coffee.
Something wrong with this tool, or missing from it? Report a bug or suggest a feature.