EQVPS
Security & certificates

CSR generator

Create a certificate signing request for any CA. The key pair is generated by WebCrypto in this tab — we never see your private key.

Runs entirely in your browser — nothing you enter is sent to our servers.

Key type

How it works

Fill in the domain and, if needed, extra names for the SAN field (every modern certificate relies on SAN, the Common Name alone isn't enough). The browser generates the key pair, builds a PKCS#10 request, signs it and gives you both files in PEM. ECDSA P-256 keys are smaller and faster; RSA 2048 is the safe choice if an old client must connect. Save the private key before closing the tab — it isn't stored anywhere.

FAQ

Is it safe to create a private key online?

It's safe when the key never leaves your device. This tool uses the browser's WebCrypto API; there's no upload step, and the Network tab stays empty during generation.

RSA or ECDSA?

ECDSA P-256 for modern servers — shorter handshakes, same security as RSA 3072. Pick RSA 2048 if you need to support very old clients or appliances.

Related tools

All tools →

Put it to use on your own server: KVM VPS from $3/month, root access, crypto payments.

VPS plans