What Is a CSR (Certificate Signing Request) and How to Generate One?

· SSL Basics

A CSR (Certificate Signing Request) is where SSL certificate issuance begins. Generated on your server, it is sent to a CA which verifies the information and returns a signed certificate.

What a CSR Contains

Common Name (domain), Organization, Organizational Unit, Locality, State, Country, and the Public Key. The accompanying private key stays on your server and is never shared.

Generating a CSR with OpenSSL

openssl req -new -newkey rsa:2048 -nodes -keyout domain.key -out domain.csr

This produces both the private key and CSR simultaneously. 2048-bit RSA is widely accepted; 4096-bit or ECDSA P-256 offer higher security.

Verify CSR contents: openssl req -text -noout -verify -in domain.csr

Private Key Security

Losing the private key renders the certificate useless — you'll need a new CSR and certificate. Store the key encrypted (with a passphrase), backed up, and access-restricted. Use HSM in production environments.

Key Pitfalls

Match the Common Name exactly to how you use the domain (with or without www, or use SAN for both). For OV/EV, organization details must match trade registry records exactly. CSR content cannot be changed after creation.

Visit the PekiSSL product page to find the right certificate for your needs.

All blog posts