FM 4-05 Chapter 4 · Security and crypto
CSR and key generator
Generate a key pair and a signed PKCS#10 request with subject and SANs, in the browser.
Local only Runs in your browser. Nothing you enter leaves this page.
Subject
Types are inferred: IPv4 and IPv6 addresses become IP, anything with @ an email (rfc822Name), the rest DNS. Force a type with a DNS:, IP: or email: prefix. Internationalised names are converted to punycode. Browsers ignore the CN and match only the SANs, so list every host name here, the CN included.
Fill in at least a common name or one subject alternative name.
The key pair is made by the browser's WebCrypto (crypto.subtle.generateKey) and the request is encoded and signed on this page. Nothing is sent or stored, and only the key type, subject and SANs go into the link. Signatures: SHA-256 with RSA, SHA-256 with P-256, SHA-384 with P-384, pure Ed25519. Not every CA accepts Ed25519 yet.