Create a Certificate Signing Request (CSR) and private key in seconds. Everything is returned to your browser over HTTPS — nothing is stored on the server.
CSR & private key are generated entirely in your browser using node-forge. Nothing is sent to any server.
www.example.com. For a wildcard, use *.example.com.US, TR).The generator creates two linked files at once. The private key stays with you and does the decryption; the CSR is a public request that carries your details and your key's public half to the Certificate Authority. The CA never sees your private key. If you lose the private key after your certificate is issued, the certificate becomes unusable and you'll need to reissue — so back it up somewhere safe before you install.
example.com and www.example.com are different hostnames. Decide which one (or both, via SAN) you actually serve.Not sure your key, CSR and certificate match after issuance? Check them with our Key-CSR-Cert Matcher before you install.
No. The CSR and key are generated and returned to your browser over HTTPS. Nothing is written to our server.
2048-bit RSA is the widely trusted default. 4096-bit RSA is stronger but slightly slower; ECDSA (P-256) is compact and fast. Any of these is accepted by SSL.com.
Yes — add each hostname as a SAN entry. A single multi-domain or wildcard certificate can then secure all of them.
No. If your hosting panel or openssl already produced a CSR, use that one. This tool is for when you don't have a way to generate one yourself.
CSR ready? Get the matching certificate in minutes.
Compare SSL plans →