SSL & Security
Certificate Generator
Generate a Certificate
Certificate validity period in days
Domain name for SSL certificates or person name for client certificates
2-letter country code
Comma-separated list of alternative names (DNS:domain.com, IP:1.2.3.4)
Tool features
Multiple Certificate Types
Strong Cryptography
Custom Subject
SAN Support
What is a self-signed certificate & how it works
A self-signed certificate is an X.509 certificate signed by its own private key instead of a public certificate authority. It encrypts traffic exactly like a CA-issued certificate, but browsers and clients will not trust it until you install it (or the CA that signed it) as trusted.
That makes self-signed and private-CA certificates a good fit for local development, internal services, test environments and mutual-TLS client authentication, and the wrong choice for a public website, which needs a certificate from a publicly trusted CA.
How to use this tool
Related tools
Frequently asked questions
DNS:localhost and IP:127.0.0.1.openssl req -x509 -newkey rsa:2048 -nodes -keyout key.pem -out cert.pem -days 365 -subj "/CN=localhost" -addext "subjectAltName=DNS:localhost".