CSR.pluscsr.plus

CSR.plus API 参考

通过一个开放 REST API 自动化完整的 SSL/TLS 证书生命周期——CSR 生成、解码、A–F 评级、证书透明度、CAA、吊销与 TLS 追踪。免费、无需认证、无需 API 密钥。

在线试玩 API

概述

CSR.plus API 是一组驱动我们网页工具的只读与生成端点。每个端点都返回 JSON、支持浏览器客户端的 CORS,并按 IP 地址限流。密钥和 CSR 仅在内存中生成,绝不存储。

你所需的一切:生成 CSR 与私钥、解码任意 CSR、为部署评级 A-F、搜索证书透明度日志、检查 CAA 记录、验证吊销状态并追踪完整的 TLS 握手。

基础 URL 与认证

Base URL
https://csr.plus

所有端点均通过 HTTPS 提供。无需认证——API 在设计上就是开放且无需认证的。没有 API 密钥、令牌或计费。请求仅按 IP 地址识别以用于限流。

所有响应都包含 CORS 头(Access-Control-Allow-Origin: *),因此你可以直接从浏览器和客户端脚本调用 API。

速率限制

端点限制窗口
/api/generate10 次请求每分钟每 IP
/api/ssl-check, /api/ct, /api/caa30 次请求每分钟每 IP
/api/revocation, /api/ssl-tracer20 次请求每分钟每 IP
/api/decode, /api/openssl-trace不限制—

超过限制会返回 HTTP 429,并附带 Retry-After 头,指示需要等待的秒数。

POST/api/generate

生成证书签名请求和私钥。速率限制:每分钟每 IP 10 次请求。

请求体

参数类型必填说明
common_namestring是主域名(例如 example.com)
sansarray否附加的主题备用名称,例如 ["www.example.com"]
organizationstring否组织名称(O)
org_unitstring否组织单位(OU)
countrystring否两位国家代码(C),例如 "US"
statestring否州或省(ST)
localitystring否城市 / 地区(L)
emailstring否联系邮箱地址
key_typestring否"rsa"(默认)或 "ecdsa"
key_sizestring|int否RSA:2048(默认)/ 3072 / 4096 · ECDSA:"P-256"(默认)/ "P-384"
passphrasestring否将私钥加密为加密的 PKCS#8 PEM(最多 200 字符)

响应字段

字段说明
csrPEM 格式的证书签名请求(PKCS#10,SHA-256 签名)
private_keyPEM 格式的私钥(PKCS#8;提供 passphrase 时为加密的 PKCS#8)
algorithm使用的算法,例如 "RSA-2048" 或 "ECDSA-P-256"
created_at生成的 ISO 8601 时间戳
请求示例(cURL)
curl -X POST https://csr.plus/api/generate \
  -H "Content-Type: application/json" \
  -d '{
    "common_name": "example.com",
    "sans": ["www.example.com", "api.example.com"],
    "organization": "Example Inc",
    "country": "US",
    "key_type": "rsa",
    "key_size": 2048
  }'
响应示例
{
  "csr": "-----BEGIN CERTIFICATE REQUEST-----\nMIICzDCCAbQCAQAwgYwxCzAJBgNVBAYTAVVT...\n-----END CERTIFICATE REQUEST-----",
  "private_key": "-----BEGIN PRIVATE KEY-----\nMIIEvQIBADANBgkqhkiG9w0BAQEFAASC...\n-----END PRIVATE KEY-----",
  "algorithm": "RSA-2048",
  "created_at": "2026-08-14T10:30:00.000Z"
}
使用 OpenSSL 验证结果
openssl req -verify -noout -in example.com.csr
openssl req -in example.com.csr -text -noout | head -20
POST/api/decode

解析任意 PKCS#10 CSR,返回其主题、主题备用名称、公钥、签名验证和扩展。

请求体

参数类型必填说明
csrstring是PEM 格式的 CSR(-----BEGIN CERTIFICATE REQUEST-----)
请求示例(cURL)
curl -X POST https://csr.plus/api/decode \
  -H "Content-Type: application/json" \
  -d '{"csr": "-----BEGIN CERTIFICATE REQUEST-----\n..."}'
响应示例
{
  "success": true,
  "subject": {
    "commonName": "example.com",
    "organization": "Example Inc",
    "organizationalUnit": null,
    "country": "US",
    "state": "California",
    "locality": "San Francisco",
    "email": null
  },
  "publicKey": { "type": "RSA", "size": 2048 },
  "signature": { "algorithm": "sha256WithRSAEncryption", "verified": true },
  "sanList": ["example.com", "www.example.com", "api.example.com"],
  "extensions": [],
  "size": 640,
  "version": 0,
  "timestamp": "2026-08-14T10:30:00.000Z"
}

注意:dcvInfo 包含域名控制验证提示(HTTP token 文件和 CNAME 记录),在完成 CA 验证步骤时很有用。

GET/api/ssl-check?domain={domain}

完整的 SSL/TLS 检测,采用 SSL Labs 风格 A–F 评级:证书有效性、主机名匹配、链信任、TLS 版本探测和 HSTS 检查。

查询参数

参数类型必填说明
domainstring是要检查的主机名(假定端口 443)
请求示例
curl "https://csr.plus/api/ssl-check?domain=example.com"
响应示例
{
  "success": true,
  "domain": "example.com",
  "grade": {
    "letter": "A+",
    "score": 100,
    "label": "Excellent configuration with HSTS",
    "checks": [
      { "name": "Hostname match", "status": "pass", "detail": "Certificate covers the requested hostname" },
      { "name": "TLS 1.3", "status": "pass", "detail": "TLS 1.3 is supported" }
    ]
  },
  "cert": {
    "subject": "CN=example.com",
    "issuer": "CN=R10,O=Let's Encrypt,C=US",
    "validFrom": "2026-05-14T00:00:00.000Z",
    "validTo": "2026-08-12T00:00:00.000Z",
    "daysRemaining": 30,
    "san": ["example.com", "www.example.com"]
  },
  "tls": { "tls13": true, "tls12": true, "tls11": false, "tls10": false, "protocol": "TLSv1.3" },
  "hsts": { "present": true, "maxAge": 31536000, "includeSubDomains": true, "preload": false }
}
GET/api/ct?domain={domain}

搜索公共证书透明度日志中曾为某域名签发的所有证书。当 crt.sh 不可用时回退到 Cert Spotter。

查询参数

参数类型必填说明
domainstring是要在 CT 日志中搜索的域名
请求示例
curl "https://csr.plus/api/ct?domain=example.com"
响应示例
{
  "success": true,
  "count": 12,
  "source": "crt.sh",
  "certs": [
    {
      "id": 123456,
      "logged_at": "2026-08-01T12:00:00.000Z",
      "not_before": "2026-07-15T00:00:00.000Z",
      "not_after": "2026-10-13T00:00:00.000Z",
      "common_name": "example.com",
      "name_value": "example.com\nwww.example.com"
    }
  ]
}

响应包含 source(crt.sh 或 certspotter),以便你了解数据来自哪个提供商。

GET/api/caa?domain={domain}

返回域名的 DNS CAA 记录以及 A、AAAA、NS 和 MX 记录,显示哪些证书颁发机构被授权签发证书。

查询参数

参数类型必填说明
domainstring是要查询的域名
请求示例
curl "https://csr.plus/api/caa?domain=example.com"
响应示例
{
  "success": true,
  "domain": "example.com",
  "caa": [
    { "flags": 0, "tag": "issue", "value": "letsencrypt.org" },
    { "flags": 0, "tag": "iodef", "value": "mailto:[email protected]" }
  ],
  "a": ["93.184.216.34"],
  "aaaa": ["2606:2800:220:1:248:1893:25c8:1946"],
  "ns": ["a.iana-servers.net"],
  "mx": [],
  "caaError": ""
}
GET/api/revocation?domain={domain}

获取域名当前提供的证书,并报告其 CRL 分发点和 OCSP 响应器端点。

查询参数

参数类型必填说明
domainstring是要检查其服务证书的域名
请求示例
curl "https://csr.plus/api/revocation?domain=example.com"
响应示例
{
  "success": true,
  "domain": "example.com",
  "serial": "03F2A1B3C4D5E6F7",
  "crlUrls": ["http://crl.letsencrypt.org/r3.crl"],
  "ocspUrls": ["http://r3.o.lencr.org"],
  "status": "good"
}
GET/api/ssl-tracer?domain={domain}&port={port}

对任意主机和端口执行真实的 TLS 握手,记录 DNS 解析、TCP 连通性、协商的 TLS 版本与密码套件,以及完整的证书链。

查询参数

参数类型必填说明
domainstring是要连接的主机名
portint否TCP 端口(默认 443)
请求示例
curl "https://csr.plus/api/ssl-tracer?domain=example.com&port=443"
响应示例
{
  "success": true,
  "host": "example.com",
  "port": 443,
  "dns": { "ips": ["93.184.216.34"], "ms": 12 },
  "tcp": { "ok": true, "ms": 38 },
  "tls": { "version": "TLSv1.3", "cipher": "TLS_AES_128_GCM_SHA256", "weak": false },
  "certs": [
    {
      "subject": { "CN": "example.com" },
      "issuer": { "CN": "R10", "O": "Let's Encrypt", "C": "US" },
      "serialNumber": "03F2A1B3C4D5E6F7",
      "notBefore": "2026-05-14T00:00:00.000Z",
      "notAfter": "2026-08-12T00:00:00.000Z",
      "daysRemaining": 30,
      "expired": false,
      "isCA": false,
      "isSelfSigned": false,
      "keyType": "RSA",
      "keySize": 2048,
      "sha256": "E8:2F:0A:..."
    }
  ],
  "chainComplete": true,
  "chainNote": "Chain resolves to a trusted root",
  "errors": []
}
GET/api/openssl-trace?domain={domain}

对域名执行一次原始的 openssl s_client 握手,并返回完整的详细输出——适合调试证书链和协议问题。

查询参数

参数类型必填说明
domainstring是要追踪的域名(假定端口 443)
请求示例
curl "https://csr.plus/api/openssl-trace?domain=example.com"
响应示例
{
  "success": true,
  "output": "CONNECTED(00000005)\ndepth=2 C=US, O=Internet Security Research Group...\nverify return:1\n..."
}

错误码

错误以 JSON 返回,包含 error 消息,在适用时还包含用于程序化处理的 errorId。

状态码errorId含义
400invalid_json请求体不是有效的 JSON
400invalid_common_namecommon_name 缺失或超过 253 个字符
400invalid_key_typekey_type 必须是 "rsa" 或 "ecdsa"
400invalid_key_sizeRSA 大小必须为 2048/3072/4096;ECDSA 曲线必须为 "P-256"/"P-384"
400invalid_passphrasepassphrase 必须是非空字符串(最多 200 字符)
400invalid_json_format请求体或字段格式错误
405method_not_allowed/api/generate 仅接受 POST
413payload_too_large请求体过大(限制 10 KB)
429rate_limit_exceeded超出速率限制——请在 Retry-After 头指定时间后重试
500generation_failed密钥/CSR 生成期间发生内部错误

最佳实践

  • 对于生产环境,请使用 OpenSSL 或 node-forge 在本地生成私钥。该 API 面向开发、测试和轻量自动化。
  • 当密钥需要在系统间存储或传输时,请设置 passphrase。
  • 除非合规要求更强密钥,否则使用 RSA 2048 或 ECDSA P-256。
  • 遵守 Retry-After 头,不要在 429 后持续请求。
  • 在调用只读端点前,先在客户端校验 domain 参数(最多 253 字符,字母数字、点和连字符)。
  • 切勿记录 API 响应中的 private_key 字段。

更多示例

Python(requests)
import requests

r = requests.post(
    "https://csr.plus/api/generate",
    json={"common_name": "example.com", "sans": ["www.example.com"]},
)
r.raise_for_status()
data = r.json()

open("example.com.csr", "w").write(data["csr"])
open("example.com.key", "w").write(data["private_key"])
Node.js(fetch)
const res = await fetch("https://csr.plus/api/generate", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({ common_name: "example.com", key_type: "ecdsa", key_size: "P-256" }),
});
const { csr, private_key } = await res.json();
console.log(csr);

在线试玩 API

选择一个端点,填写参数,即可对生产 API 发起真实请求。

常见问题

API 的速率限制是多少?

CSR 生成允许每 IP 每分钟 10 次请求。SSL 检测、CT 和 CAA 允许每分钟 30 次;吊销和 TLS 追踪器允许每分钟 20 次。超过限制会返回带 Retry-After 头的 HTTP 429。

支持哪些密钥类型?

RSA 2048/3072/4096 和 ECDSA P-256/P-384。在请求体中传入 key_type 和 key_size 参数。

可以加密生成的私钥吗?

可以。在请求中添加 passphrase 字段,私钥将作为加密的 PKCS#8 PEM 密钥返回。

API 会存储我的私钥吗?

不会。密钥和 CSR 在内存中生成,从不持久化、记录或写入磁盘。请将该 API 用于开发和测试。

哪些 CA 接受此 API 生成的 CSR?

该 API 生成带有 SHA-256 签名的标准 PKCS#10 CSR,所有主流证书颁发机构都接受,包括 Let’s Encrypt、DigiCert、Sectigo 和 Google Trust Services。