What Is a CSR (Certificate Signing Request) and How to Generate One?
· SSL Basics
A CSR (Certificate Signing Request) is where SSL certificate issuance begins. Generated on your server, it is sent to a CA which verifies the information and returns a signed certificate.
What a CSR Contains
Common Name (domain), Organization, Organizational Unit, Locality, State, Country, and the Public Key. The accompanying private key stays on your server and is never shared.
Generating a CSR with OpenSSL
openssl req -new -newkey rsa:2048 -nodes -keyout domain.key -out domain.csr
This produces both the private key and CSR simultaneously. 2048-bit RSA is widely accepted; 4096-bit or ECDSA P-256 offer higher security.
Verify CSR contents: openssl req -text -noout -verify -in domain.csr
Private Key Security
Losing the private key renders the certificate useless — you'll need a new CSR and certificate. Store the key encrypted (with a passphrase), backed up, and access-restricted. Use HSM in production environments.
Key Pitfalls
Match the Common Name exactly to how you use the domain (with or without www, or use SAN for both). For OV/EV, organization details must match trade registry records exactly. CSR content cannot be changed after creation.
Visit the PekiSSL product page to find the right certificate for your needs.