SSL & Security

Certificate Generator

X.509 Certificates

Generate a Certificate

Generate X.509 certificates for development, testing, and secure communications.
Quick Presets
Web Server SSL
SSL/TLS certificate for web servers
Development CA
Certificate Authority for development
Client Authentication
Client certificate for authentication
Code Signing
Certificate for signing code

Certificate validity period in days

Certificate Subject

Domain name for SSL certificates or person name for client certificates

2-letter country code

Comma-separated list of alternative names (DNS:domain.com, IP:1.2.3.4)

Key Usage
Extended Key Usage

Tool features

Professional certificate generation for secure communications
4 features

Multiple Certificate Types

Generate SSL, CA, client, and code signing certificates

Strong Cryptography

RSA and ECDSA key algorithms with various key sizes

Custom Subject

Configurable certificate subject and extensions

SAN Support

Subject Alternative Names for multi-domain certificates

What is a self-signed certificate & how it works

When a certificate you sign yourself is the right tool

A self-signed certificate is an X.509 certificate signed by its own private key instead of a public certificate authority. It encrypts traffic exactly like a CA-issued certificate, but browsers and clients will not trust it until you install it (or the CA that signed it) as trusted.

That makes self-signed and private-CA certificates a good fit for local development, internal services, test environments and mutual-TLS client authentication, and the wrong choice for a public website, which needs a certificate from a publicly trusted CA.

Self-signed
Issuer and subject are the same; trusted only where you install it manually.
CA certificate
A certificate allowed to sign others (basicConstraints CA:TRUE), for a private PKI.
Key usage
Extensions that limit a certificate to server auth, client auth, code signing and so on.

How to use this tool

Create a certificate and key in four steps
1
Pick a preset or type
Start from Web Server SSL, Development CA, Client Authentication or Code Signing, or choose the type yourself.
2
Fill in the subject
Enter the Common Name and any organisation details, and list every hostname or IP in the Subject Alternative Names.
3
Choose key and validity
Select RSA or ECDSA, the key size or curve, and how many days the certificate should be valid.
4
Generate and download
Generate the certificate and private key, then download both and keep the key private.

Frequently asked questions

Common questions about generating certificates
5 Q&A

For local development, internal tools, lab and test environments, and client certificates inside your own infrastructure. For any public website use a certificate from a trusted CA such as Let’s Encrypt, or visitors will see a security warning.

Browsers only trust certificates that chain to a root in their trust store. A self-signed certificate has no such chain, so you must add it (or your private CA certificate) to the operating system or browser trust store on each machine that should accept it.

Yes. Modern browsers ignore the Common Name and only match hostnames against the SAN list, so include every hostname and IP address the certificate will serve, e.g. DNS:localhost and IP:127.0.0.1.

RSA 2048 or 3072 is the most compatible choice. ECDSA P-256 gives equivalent security with much smaller keys and faster handshakes, and is supported by all current clients.

Run openssl req -x509 -newkey rsa:2048 -nodes -keyout key.pem -out cert.pem -days 365 -subj "/CN=localhost" -addext "subjectAltName=DNS:localhost".