Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Generate private keys and CSRs with OpenSSL

From Tech-Wiki


Generate private keys, PKCS#10 certificate signing requests (CSRs) and test self-signed certificates using current OpenSSL command syntax.

ⓘ
Validation status
Reviewed against current OpenSSL 3.x openssl req documentation on 27 September 2026.
!
Private-key handling
Protect generated private keys and any passphrases used to encrypt them. Do not copy production private keys into tickets, chat systems, source repositories or other uncontrolled locations.

Generate a new key and CSR

This command generates a new RSA private key and a CSR in one operation. By default, OpenSSL can protect the generated private key with a passphrase.

>_Generate an RSA key and CSR
openssl req -newkey rsa:2048 -keyout server.key -out server.csr

Enter the requested subject information when prompted, or use an approved OpenSSL configuration for repeatable deployments.

Generate a CSR from an existing key

>_Generate a CSR using an existing private key
openssl req -new -key server.key -out server.csr

Inspect and verify the CSR

>_Display and verify a CSR
openssl req -in server.csr -text -verify -noout

Review the subject and requested extensions before submitting the CSR to a certificate authority.

Unencrypted service keys

Some unattended services require a private key that can be read without an interactive passphrase. OpenSSL 3.x uses -noenc when a newly generated key must be written unencrypted.

!
Only remove key encryption where required
An unencrypted private key relies entirely on filesystem and host security. Restrict access to the key file and use this approach only where the service design requires it.
>_Generate an unencrypted RSA key and CSR
openssl req -newkey rsa:2048 -noenc -keyout server.key -out server.csr

The older -nodes option is deprecated in OpenSSL 3.x.

Create a self-signed test certificate

For lab or test use, openssl req -x509 can create a self-signed certificate.

>_Create a short-lived self-signed test certificate
openssl req -x509 -newkey rsa:2048 -keyout server.key -out server.crt -days 30

For services accessed by DNS name, include the required subject alternative names using your approved OpenSSL configuration or appropriate -addext options.

ⓘ
Production certificates
Self-signed certificates are useful for controlled testing but do not replace certificates issued through the trust model required by the production environment.

Official references

See also