SSL & Security

Certificate CSR Matcher

CSR Match

Match Certificate & CSR

Paste your SSL certificate and CSR to verify if they match and were generated from the same private key.

SSL Certificate

Paste the complete certificate including BEGIN and END markers

Certificate Signing Request (CSR)

Paste the complete CSR including BEGIN and END markers

Tool features

Comprehensive certificate and CSR analysis with security verification
4 checks

Certificate Analysis

Parse and analyze X.509 certificates for key information and validity

CSR Verification

Validate Certificate Signing Requests and extract subject information

Match Verification

Compare certificates and CSRs to verify they were generated from the same private key

Security Validation

Ensure certificate and CSR integrity with cryptographic verification

What is certificate–CSR matching & how it works

Why a certificate only works with the key behind its CSR

A Certificate Signing Request (CSR) carries the public key of a key pair you generated, and the CA copies that public key into the certificate it issues. A certificate and CSR therefore "match" when they contain the same public key, which proves the certificate belongs to the private key sitting on your server.

Comparing the two means comparing their public keys, with the subject fields as a secondary check. A mismatch usually means the CSR was regenerated after ordering, or the certificate was issued for a different request.

CSR
A signed request holding your public key and subject details, sent to a CA.
Public key modulus
The unique part of an RSA public key; identical values mean the same key pair.
Subject
The CN, O, OU and other identity fields copied from the CSR into the certificate.

How to use this tool

Check whether a certificate was issued from your CSR in four steps
1
Paste the certificate
Paste the issued certificate in PEM format, including the BEGIN/END CERTIFICATE lines.
2
Paste the CSR
Paste the CSR you submitted to the CA, including the BEGIN/END CERTIFICATE REQUEST lines.
3
Compare
Run the match to compare the public keys and the subject fields side by side.
4
Act on the result
On a match, install the certificate with the private key from that CSR; on a mismatch, find the right CSR or reissue.

Frequently asked questions

Common questions about certificate and CSR matching
5 Q&A

They match when both contain the same public key. For RSA that means the same modulus. You can confirm it locally with openssl req -noout -modulus -in server.csr | openssl md5 and the same command with x509 on the certificate.

The most common causes are generating a new CSR (and key) after placing the order, pasting a CSR from another server, or the CA reissuing against a different request. The certificate only works with the private key that belongs to the CSR it was issued from.

Not necessarily. CAs often drop or rewrite fields such as OU, locality or email, and DV certificates may keep only the Common Name. The public key is what must match; subject differences are shown for information.

Yes. Certificates and CSRs only contain public information and never include the private key. Never paste a private key into any online tool.

Locate the private key that was created with the original CSR, or generate a new key and CSR and ask your CA to reissue the certificate. Most CAs reissue for free during the certificate lifetime.