Generate private keys and CSRs with OpenSSL
More actions
Generate private keys, PKCS#10 certificate signing requests (CSRs) and test self-signed certificates using current OpenSSL command syntax.
openssl req documentation on 27 September 2026.Generate a new key and CSR
This command generates a new RSA private key and a CSR in one operation. By default, OpenSSL can protect the generated private key with a passphrase.
openssl req -newkey rsa:2048 -keyout server.key -out server.csr
Enter the requested subject information when prompted, or use an approved OpenSSL configuration for repeatable deployments.
Generate a CSR from an existing key
openssl req -new -key server.key -out server.csr
Inspect and verify the CSR
openssl req -in server.csr -text -verify -noout
Review the subject and requested extensions before submitting the CSR to a certificate authority.
Unencrypted service keys
Some unattended services require a private key that can be read without an interactive passphrase. OpenSSL 3.x uses -noenc when a newly generated key must be written unencrypted.
openssl req -newkey rsa:2048 -noenc -keyout server.key -out server.csr
The older -nodes option is deprecated in OpenSSL 3.x.
Create a self-signed test certificate
For lab or test use, openssl req -x509 can create a self-signed certificate.
openssl req -x509 -newkey rsa:2048 -keyout server.key -out server.crt -days 30
For services accessed by DNS name, include the required subject alternative names using your approved OpenSSL configuration or appropriate -addext options.