OpenSSL Command Builder

Pick a task and your platform, get the exact command to run on your own machine — then paste the output back to have it explained. Keys never touch a website.

Runs entirely in your browser. Your browser blocks this page from opening connections or loading anything from other sites. Nothing you enter is uploaded or saved.

requests since opened: 0
How to verify this yourself
  1. Open your browser’s developer tools (F12, or ⌥⌘I on Mac) → Network tab, then use the tool. No new requests appear.
  2. Or disconnect from the internet after the page loads — the tool keeps working, because it never needed the network.
  3. See the rule itself: in the Network tab, select this page’s document → Response Headers → content-security-policy contains connect-src 'none' and no 'unsafe-inline' for scripts.
  4. Press Test the lock: the page tries a harmless request and the browser blocks it (the Console shows the refusal).
How to use
  1. Pick your platform and a task, and fill in names and file paths.
  2. Copy the command and run it in your terminal.
  3. Paste the output back to get it explained, including common errors.
Your platform
Linux, Homebrew (brew install openssl), Git Bash on Windows

Generate a private key and CSR

The request you send to a certificate authority. The private key stays on your machine.

Comma-separated. IP addresses are detected. The common name is added automatically.

Run in your terminal

Create the key and the CSR
openssl req -new -newkey rsa:2048 -keyout www.example.com.key -out www.example.com.csr -subj /CN=www.example.com -addext subjectAltName=DNS:www.example.com,DNS:example.com
Make the key readable only by you
chmod 600 www.example.com.key
Check the CSR before sending it
openssl req -in www.example.com.csr -noout -text -verify

! Keep the .key file private. Only the .csr goes to the certificate authority.

What a correct result looks like

The last command prints a "verify OK" line followed by the subject and the Subject Alternative Names you asked for. You can also paste the .csr into the Certificate & CSR Decoder.

What the flags do

req -new
Create a certificate signing request
-newkey
Generate a new private key of this type at the same time
-keyout / -out
Where to write the private key and the CSR
-subj
The subject name, so OpenSSL does not ask interactively
-addext subjectAltName
The names browsers actually check. Required for public TLS certificates

Not sure which you have? Run openssl version: it prints “OpenSSL 3…”, “OpenSSL 1.1.1…” or “LibreSSL…”. Check commands before running them, especially output paths that would overwrite files.

Common questions

How do I create a CSR with subject alternative names?

Choose “Generate a private key and CSR”, enter the host names, and copy the command for your platform: OpenSSL 3, OpenSSL 1.1, LibreSSL on macOS, or Windows.

How do I check that a key matches a certificate?

Use the key-match task: it compares the public key inside the certificate with the one derived from your private key, on your own machine. The private key never touches a website.

What does “unable to get local issuer certificate” mean?

The chain is incomplete: the server or file is missing an intermediate certificate. Paste your command’s output into “Paste the output back” for an explanation and a fix.

Known limitations

  • Commands are generated here and run on your machine — check them before running, especially file paths you will overwrite.
  • OpenSSL 3, OpenSSL 1.1.1 and macOS LibreSSL commands are tested; Windows commands follow Microsoft’s documentation but have not been run on Windows yet.
  • Output explanations cover the common OpenSSL messages, not every possible error.
  • Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works

tools v0.9.0 · build 7317bbb · 2026-10-07