How to Generate a CSR
· CSR.plus Team

- •A CSR is a public key plus identity data signed with your private key — the first step toward any SSL certificate.
- •One command per platform: OpenSSL for Nginx/Apache, IIS Manager for Windows, cPanel for shared hosting.
- •Choose a 2048-bit RSA or 256-bit ECDSA key; never share your private key with anyone, including your CA.
What a CSR is
A Certificate Signing Request is a file containing your public key and the identity you want certified: common name (the domain), organization, locality and country. It is signed with your private key so the CA can verify that you control the key pair. After the CA issues your certificate, the CSR itself is no longer needed.
Generate with OpenSSL
For Nginx, Apache and most Linux stacks, run: openssl req -new -newkey rsa:2048 -nodes -keyout domain.key -out domain.csr. The -nodes flag keeps the key unencrypted so your web server can load it without a passphrase prompt. Answer the prompts; the Common Name must be your exact domain, such as www.example.com.
Generate on other platforms
In IIS, use Server Certificates → Create Certificate Request and complete the Distinguished Name fields. In cPanel, open Security → SSL/TLS → Generate, view, or delete SSL certificate signing requests. In the Windows certificate wizard and most panel UIs, the same identity fields are collected and the request is written automatically.
Key size and algorithm
RSA 2048 is the safe default: universally compatible and fast enough for almost every workload. Choose RSA 4096 only if a compliance rule requires it. ECDSA with a P-256 key offers smaller handshakes and lower CPU cost, but check that your clients and CDN support it first.
Next steps after the CSR
Submit the CSR text to your CA, complete validation, and install the issued certificate together with the intermediate chain. Use our SSL Checker afterwards to confirm the chain, key match and expiry, and the Certificate Inspector for a full chain audit.
FAQ
Is the CSR the same as the private key?
No. The CSR contains only your public key and identity data. The private key stays on your server and must never be sent anywhere — not even to your CA.
What should the Common Name be?
The exact domain you are securing, without protocol or path, for example www.example.com. For wildcard certificates use *.example.com.
Can I reuse a CSR?
CSRs are valid for about 30 days with most CAs and can often be reused within that window. After expiration, simply generate a new one with the same key.
UptimeRobot
Monitor your SSL & uptime for free
UptimeRobot watches your certificates and endpoints 24/7 — 50 monitors on the free plan.
Affiliate link — we may earn a commission at no extra cost to you.
Free SSL/TLS tools
Verify and inspect your certificates in seconds.