OpenSSL Command Builder
Pick a task and your platform, get the exact command to run on your own machine — then paste the output back to have it explained. Keys never touch a website.
How to use
- Pick your platform and a task, and fill in names and file paths.
- Copy the command and run it in your terminal.
- Paste the output back to get it explained, including common errors.
Generate a private key and CSR
The request you send to a certificate authority. The private key stays on your machine.
Comma-separated. IP addresses are detected. The common name is added automatically.
Run in your terminal
openssl req -new -newkey rsa:2048 -keyout www.example.com.key -out www.example.com.csr -subj /CN=www.example.com -addext subjectAltName=DNS:www.example.com,DNS:example.com
chmod 600 www.example.com.key
openssl req -in www.example.com.csr -noout -text -verify
! Keep the .key file private. Only the .csr goes to the certificate authority.
What a correct result looks like
The last command prints a "verify OK" line followed by the subject and the Subject Alternative Names you asked for. You can also paste the .csr into the Certificate & CSR Decoder.
What the flags do
- req -new
- Create a certificate signing request
- -newkey
- Generate a new private key of this type at the same time
- -keyout / -out
- Where to write the private key and the CSR
- -subj
- The subject name, so OpenSSL does not ask interactively
- -addext subjectAltName
- The names browsers actually check. Required for public TLS certificates
Not sure which you have? Run openssl version: it prints “OpenSSL 3…”, “OpenSSL 1.1.1…” or “LibreSSL…”. Check commands before running them, especially output paths that would overwrite files.
Common questions
How do I create a CSR with subject alternative names?
Choose “Generate a private key and CSR”, enter the host names, and copy the command for your platform: OpenSSL 3, OpenSSL 1.1, LibreSSL on macOS, or Windows.
How do I check that a key matches a certificate?
Use the key-match task: it compares the public key inside the certificate with the one derived from your private key, on your own machine. The private key never touches a website.
What does “unable to get local issuer certificate” mean?
The chain is incomplete: the server or file is missing an intermediate certificate. Paste your command’s output into “Paste the output back” for an explanation and a fix.
Known limitations
- Commands are generated here and run on your machine — check them before running, especially file paths you will overwrite.
- OpenSSL 3, OpenSSL 1.1.1 and macOS LibreSSL commands are tested; Windows commands follow Microsoft’s documentation but have not been run on Windows yet.
- Output explanations cover the common OpenSSL messages, not every possible error.
- Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works
Related reading on CipherMind
Standards & references
- OpenSSL 3 command reference (opens in a new tab)
- LibreSSL openssl(1) (opens in a new tab)
- Microsoft certreq (opens in a new tab)
- Microsoft certutil (opens in a new tab)
- New-SelfSignedCertificate (opens in a new tab)