How to Generate a CSR (Certificate Signing Request) for SSL
Table of Contents
- 1 How to Generate a CSR (Certificate Signing Request) for SSL
- 2 What is a CSR and Why You Need One
- 3 Before You Start: Information Checklist
- 4 Choose Your Generation Method
- 5 Understanding CSR Fields
- 6 Special Certificate Types
- 7 Troubleshooting Common Issues
- 8 After Generation: Next Steps
- 9 Quick Command Reference
- 10 Managed SSL Hosting: The Easier Alternative
- 11 Conclusion
- 12 Frequently Asked Questions
Seeing “Not Secure” in your browser can instantly kill visitor trust. An SSL certificate fixes this, but first you need a Certificate Signing Request (CSR).
A CSR is your application for an SSL certificate. It contains your website’s public key and business details that Certificate Authorities (CAs) verify before issuing your certificate. This guide shows you exactly how to create one, regardless of your technical level.
Need help? Contact our support team at +91-080 6225 6100
What is a CSR and Why You Need One
Think of a CSR as a digital passport application. You provide your information, the CA verifies it, and issues your SSL certificate. Without a valid CSR, you can’t get an SSL certificate.
| Component | What It Does |
|---|---|
| Public Key | Encrypts data between your server and visitors’ browsers |
| Your Domain | The website address being secured (e.g., www.example.com) |
| Organization Info | Your business name, location, and contact details |
| Digital Signature | Proves the request hasn’t been tampered with |
Before You Start: Information Checklist
Gather these details before generating your CSR (typos can invalidate your request):
- Domain name – Exactly as it appears: www.example.com or example.com
- Company legal name – Must match official registration: “ABC Technologies Pvt Ltd”
- Department – Optional for basic certificates: “IT Department”
- City – Full name: “Mumbai” (not abbreviations)
- State/Province – Spelled out completely: “Maharashtra” (never “MH”)
- Country code – Two letters: “IN” for India, “US” for United States
- Email – For certificate notifications: [email protected]
Pro Tip: Save these in a text file. You’ll enter them during CSR generation, and mistakes mean starting over.
Choose Your Generation Method
Pick the method that matches your setup:
| Your Situation | Best Method | Difficulty |
|---|---|---|
| Using cPanel / Plesk hosting | Control panel interface | ⭐ Easiest |
| Have SSH access to server | OpenSSL command line | ⭐⭐ Moderate |
| Windows Server with IIS | IIS Manager | ⭐⭐ Moderate |
| No server access | Online CSR generator | ⭐ Easy (less secure) |
Perfect for shared hosting users and first-time SSL installers.
- Log into cPanel (yourdomain.com/cpanel or through your host’s portal)
- Find “Security” section → Click “SSL/TLS”
- Select “Certificate Signing Requests (CSR)”
- Fill out the form with your prepared information:
- Domain: www.example.com
- Company: ABC Technologies Pvt Ltd
- City: Mumbai
- State: Maharashtra
- Country: IN
- Email: [email protected]
- Key Size: 2048 (minimum) or 4096 (better security)
- Click “Generate”
- Save both files immediately:
- CSR (submit to Certificate Authority)
- Private Key (store securely, never share)
Security Warning: Your private key is generated with the CSR. If you lose it, you’ll need to start over completely. Store it in an encrypted, password-protected location.
For developers and system administrators with server access.
Single command to generate both CSR and private key:
openssl req -new -newkey rsa:2048 -nodes -keyout domain.key -out domain.csr
What each part means:
- req -new = Create new certificate request
- -newkey rsa:2048 = Generate 2048-bit key (use 4096 for higher security)
- -nodes = Don’t password-protect the key (allows automatic server restarts)
- -keyout domain.key = Save private key as “domain.key”
- -out domain.csr = Save CSR as “domain.csr”
You’ll answer these prompts:
- Country Name: IN
- State or Province: Maharashtra
- Locality Name: Mumbai
- Organization Name: Your Company Ltd
- Organizational Unit: IT Department
- Common Name: www.yourdomain.com ← MUST match your domain exactly
- Email Address: [email protected]
Critical: The Common Name must be exact. For standard sites use www.example.com. For wildcard certificates covering all subdomains, use *.example.com.
Platform-Specific Commands:
- Apache Server:
cd /etc/ssl/certs
openssl req -new -newkey rsa:2048 -nodes -keyout apache.key -out apache.csr
- Nginx Server:
cd /etc/nginx/ssl
openssl req -new -newkey rsa:2048 -nodes -keyout nginx.key -out nginx.csr
For Windows Server administrators.
- Open IIS Manager (Start → Administrative Tools → IIS)
- Select your server name in left panel
- Double-click “Server Certificates”
- Click “Create Certificate Request” (right panel)
- Fill out the form with your details
- Choose “Microsoft RSA SChannel” provider
- Set bit length to 2048 (minimum) or 4096
- Save your CSR file (e.g., yourdomain.csr)
IIS stores your private key automatically in the Windows Certificate Store.
Understanding CSR Fields
Each field serves a specific purpose. Certificate Authorities verify these details, so accuracy matters.
| Field | What to Enter | Example | Why It Matters |
|---|---|---|---|
| Common Name (CN) | Your exact domain | www.example.com | Most critical – must match perfectly |
| Organization (O) | Legal business name | ABC Technologies Pvt Ltd | Verified against official records |
| Organizational Unit (OU) | Department | IT Department | Optional for basic certificates |
| Country (C) | 2-letter code | IN | Must use ISO codes (IN, US, GB, etc.) |
| State (ST) | Full state name | Maharashtra | Never abbreviate (not “MH”) |
| City (L) | Business city | Mumbai | Must match business location |
| Admin contact | [email protected] | Receives certificate notifications |
Domain Validation (DV) : Fastest
- Validates domain ownership only
- Processing: 5-10 minutes
- Best for: Blogs, personal sites, small businesses
Organization Validation (OV) : Business Verified
- Validates business registration
- Processing: 1-3 business days
- Best for: Company websites, e-commerce
Extended Validation (EV) : Maximum Trust
- Comprehensive legal verification
- Processing: 3-7 business days
- Best for: Banks, major e-commerce (shows company name in browser)
Special Certificate Types
- Common Name: *.example.com
- Covers: www.example.com, mail.example.com, shop.example.com, blog.example.com
- Limitation: Only one level deep (won’t cover secure.shop.example.com)
Wildcard Certificates secure unlimited subdomains:
- Primary domain: example.com
- Additional domains: example.net, example.org, shop-example.com
- Typically supports 3-100+ domains in one certificate
Multi-Domain (SAN) Certificates secure different domains:
Troubleshooting Common Issues
Quick fixes for frequent problems:
| Problem | Cause | Solution |
|---|---|---|
| “Invalid CSR” error from CA | Missing header/footer lines | Copy entire CSR including —–BEGIN CERTIFICATE REQUEST—– and —–END CERTIFICATE REQUEST—– |
| Private key doesn’t match CSR | Generated separately | Always generate key and CSR together in one step |
| Special characters rejected | Non-standard characters | Use only A-Z, 0-9, spaces, and basic punctuation |
| “Key size insufficient” | 1024-bit key used | Regenerate with minimum 2048-bit (4096-bit recommended) |
Verify Your CSR is Correct
Check if private key and CSR match:
# Compare these two hash values - they must be identical
openssl rsa -modulus -in domain.key -noout | openssl md5
openssl req -modulus -in domain.csr -noout | openssl md5
View CSR contents:
openssl req -text -noout -in domain.csr
Look for:
- Subject line with all your organization details
- Public-Key showing 2048 or 4096 bits
- Signature Algorithm: sha256WithRSAEncryption or better
After Generation: Next Steps
- Submit to Certificate Authority
- Complete Validation
- DV:
- OV:
- EV:
- Download Your Certificate
- Primary certificate (yourdomain.crt)
- Intermediate certificate (intermediate.crt)
- Sometimes a root certificate
- Organize Your Files
- Security checklist:
Choose a CA (DigiCert, Sectigo, Let’s Encrypt, etc.) and paste your entire CSR into their order form.
Depending on certificate type:
Respond to verification email, add DNS record, or upload HTTP file
Provide business documents and confirm phone number
Submit legal documents and complete identity verification
You’ll receive:
Keep these organized and backed up:
yourdomain_2026.key ← Private key (never share)
yourdomain_2026.csr ← CSR (archive after use)
yourdomain_2026.crt ← Certificate (install on server)
intermediate_2026.crt ← Chain certificate (required)
✅ Store private key in encrypted backup
✅ Never email or share private key
✅ Keep backups in multiple secure locations
✅ Limit access to authorized admins only
Understanding processing times helps plan website launches:
- Domain Validation (DV): 5-10 minutes
- Organization Validation (OV): 1-3 business days
- Extended Validation (EV): 3-7 business days
Quick Command Reference
Common CSR generation scenarios:
# Standard CSR with new 2048-bit key
openssl req -new -newkey rsa:2048 -nodes -keyout domain.key -out domain.csr
# Enhanced security with 4096-bit key
openssl req -new -newkey rsa:4096 -nodes -keyout domain.key -out domain.csr
# CSR using existing private key
openssl req -new -key existing.key -out domain.csr
# Wildcard CSR (enter *.yourdomain.com as Common Name)
openssl req -new -newkey rsa:2048 -nodes -keyout wildcard.key -out wildcard.csr
# View CSR details
openssl req -text -noout -in domain.csr
# Verify CSR is valid
openssl req -verify -in domain.csr -noout
Managed SSL Hosting: The Easier Alternative
While understanding CSR generation is valuable, modern managed hosting automates the entire process. Professional hosts handle certificate generation, installation, renewal, and security updates automatically.
Benefits of managed SSL:
- Zero-touch automatic renewals (no expiration surprises)
- Expert configuration and troubleshooting
- 24/7 security monitoring and updates
- No technical SSL knowledge required
- Focus on your business instead of certificate management
For businesses prioritizing time and reliability, managed SSL solutions provide enterprise-grade security without the complexity.
Conclusion
Generating a CSR is your first step toward securing your website with SSL. Whether you use cPanel’s simple interface, OpenSSL’s powerful command line, or IIS Manager’s Windows integration, the process follows the same principles: prepare accurate information, generate securely, and protect your private key.
SSL certificates are essential in 2026 for protecting user data, building trust, improving SEO rankings, and meeting compliance requirements. The “Not Secure” warning drives visitors away before they see your content.
Choose the method matching your technical comfort level and hosting environment. Beginners benefit from control panel interfaces, while advanced users appreciate command-line flexibility. But never compromise on SSL protection regardless of which method you choose.
Ready to simplify SSL management? Consider hosting solutions that handle the technical complexity automatically, letting you focus on growing your business.
Need personalized help? Our expert support team is available at +91-080 6225 6100
Frequently Asked Questions
A CSR is a file containing your website’s public key and essential details like domain, organization, and location. It’s required by a Certificate Authority to issue an SSL certificate. Without a valid CSR, you cannot secure your site with SSL.
You’ll need your exact domain name, organization name, department, city, state, country code, and a valid email address. Preparing this in advance helps avoid typos and delays in SSL installation.
If you’re a beginner, cPanel is the easiest method. Advanced users may prefer OpenSSL via the command line. Windows server users can use IIS Manager, and those without server access can try online CSR generators.
If you lose the private key, your SSL certificate will no longer work, and you’ll need to regenerate both the CSR and private key. Always store them securely and never share your private key.
Yes. Use a wildcard CSR to secure all subdomains under a domain (e.g., *.example.com), or a multi-domain (SAN) CSR to secure different domain names within one certificate.
-
KINGSTON AJITH
Senior Content Writer @ HostingRajaA seasoned Senior Content Writer with over 5 years of experience in the tech industry, specializing in web hosting. Passionate about creating unique, high-quality content for articles, blogs, and web pages. As a dedicated learner, continually improving writing skills and overseeing all online content and communications to ensure quality and consistency.