CSR Creation and Management
Certificate Signing Requests (CSRs) are essential for requesting certificates from Certificate Authorities (CAs). They contain your public key and identifying information without including your private key.
Creating a Certificate Signing Request (CSR)
# Generate a new private key and CSR (interactive mode)
openssl req -new -newkey rsa:4096 -nodes -keyout private.key -out request.csr
# Generate a CSR from an existing private key (interactive mode)
openssl req -new -key private.key -out request.csr
# Generate a CSR with subject information (non-interactive)
openssl req -new -key private.key -out request.csr \
-subj "/C=US/ST=State/L=City/O=Organization/OU=Department/CN=example.com"
# Generate a CSR with SHA-256 signature (recommended)
openssl req -new -key private.key -out request.csr -sha256 \
-subj "/C=US/ST=State/L=City/O=Organization/CN=example.com"
# Generate a CSR with modern parameters
openssl req -new -key private.key -out request.csr -sha256 \
-subj "/C=US/ST=State/L=City/O=Organization/CN=example.com" \
-addext "subjectAltName=DNS:example.com,DNS:www.example.com" \
-addext "keyUsage=digitalSignature,keyEncipherment" \
-addext "extendedKeyUsage=serverAuth"
Tip
Important fields in subject information:
- C: Country (2-letter code, e.g., US, GB, DE)
- ST: State/Province
- L: Locality/City
- O: Organization
- OU: Organizational Unit (department)
- CN: Common Name (your domain name)
- emailAddress: Administrative contact
Adding Subject Alternative Names (SANs)
Most certificate authorities require SANs in CSRs for modern TLS certificates:
# Create a configuration file for SAN
cat > san.conf << EOF
[req]
distinguished_name = req_distinguished_name
req_extensions = v3_req
prompt = no
[req_distinguished_name]
C = US
ST = State
L = City
O = Organization
OU = Department
CN = example.com
[v3_req]
basicConstraints = CA:FALSE
keyUsage = digitalSignature, keyEncipherment
extendedKeyUsage = serverAuth
subjectAltName = @alt_names
[alt_names]
DNS.1 = example.com
DNS.2 = www.example.com
DNS.3 = mail.example.com
DNS.4 = *.example.com
IP.1 = 192.168.1.1
EOF
# Generate a CSR with SANs
openssl req -new -key private.key -out san_request.csr -config san.conf
# Generate a CSR and private key in one command with SANs
openssl req -new -newkey rsa:4096 -nodes -keyout private.key \
-out san_request.csr -config san.conf
Important
Most commercial CAs have specific requirements for CSRs:
- Using strong key sizes (2048 bits minimum, 4096 bits recommended)
- Including all domains in SANs (even the primary domain)
- Using business validation information in the Organization field
- Using SHA-256 signatures (not SHA-1)
Signing the CSR yourself rather than sending it to a commercial CA comes with one significant caveat.
Warning
If you sign this CSR with your own CA using openssl ca, the SANs are discarded unless the CA configuration sets copy_extensions = copy. Signing appears to succeed and the certificate looks correct — only the SANs are missing, and clients then reject it with a name mismatch. See Issue a Server Certificate. Commercial CAs are unaffected; they build extensions from your validated order, not from the CSR.
Verifying a CSR
Always verify your CSR before submitting it to a CA:
# View complete CSR information
openssl req -in request.csr -text -noout
# Verify CSR signature (checks if the CSR is valid)
openssl req -in request.csr -verify -noout
# View CSR subject information
openssl req -in request.csr -subject -noout
# Check SANs in the CSR
openssl req -in request.csr -text -noout | grep -A 1 "Subject Alternative Name"
# Extract the public key from a CSR
openssl req -in request.csr -noout -pubkey > pubkey.pem
# Check key size and algorithm
openssl req -in request.csr -noout -text | grep "Public-Key"
CSR Submission Process
The typical process for obtaining a certificate from a commercial CA:
- Generate a CSR with appropriate information and SANs
- Submit the CSR to your chosen Certificate Authority
- Complete domain validation (DV), organization validation (OV), or extended validation (EV)
- Receive and install the signed certificate and any intermediate certificates
# Domain validation methods typically include:
# - Email validation (to admin@, webmaster@, etc.)
# - DNS TXT record validation
# - HTTP file validation (place a file on your web server)
# Example of HTTP file validation
# 1. CA provides you with a token value
# 2. Create a file at http://example.com/.well-known/pki-validation/token.txt
# 3. CA verifies the file to prove domain ownership
CSR Templates for Different Purposes
Different certificate types require different CSR configurations:
Web Server (TLS/SSL) Certificate CSR
cat > web_server.conf << EOF
[req]
distinguished_name = req_distinguished_name
req_extensions = v3_req
prompt = no
[req_distinguished_name]
C = US
ST = State
L = City
O = Organization
CN = example.com
[v3_req]
basicConstraints = CA:FALSE
keyUsage = digitalSignature, keyEncipherment
extendedKeyUsage = serverAuth, clientAuth
subjectAltName = @alt_names
[alt_names]
DNS.1 = example.com
DNS.2 = www.example.com
EOF
Email (S/MIME) Certificate CSR
cat > email.conf << EOF
[req]
distinguished_name = req_distinguished_name
req_extensions = v3_req
prompt = no
[req_distinguished_name]
C = US
ST = State
L = City
O = Organization
CN = John Doe
emailAddress = john.doe@example.com
[v3_req]
basicConstraints = CA:FALSE
keyUsage = digitalSignature, keyEncipherment, dataEncipherment
extendedKeyUsage = emailProtection, clientAuth
EOF
Code Signing Certificate CSR
cat > code_signing.conf << EOF
[req]
distinguished_name = req_distinguished_name
req_extensions = v3_req
prompt = no
[req_distinguished_name]
C = US
ST = State
L = City
O = Organization
CN = Organization Code Signing
[v3_req]
basicConstraints = CA:FALSE
keyUsage = digitalSignature
extendedKeyUsage = codeSigning
EOF
These templates can be used with the standard CSR generation command:
openssl req -new -newkey rsa:4096 -nodes -keyout private.key -out request.csr -config template.conf
Navigation
◄ Private Key Management · OpenSSL Guide · Certificate Conversions ►