A comprehensive guide to generating standard Certificate Signing Requests (CSR) and secure private keys using OpenSSL, Windows IIS certreq, and cPanel.
A Certificate Signing Request (CSR) is a standardized block of encoded text (RFC 2986 / PKCS#10) sent to a Certificate Authority (CA) to purchase or renew an SSL certificate. It encapsulates your organization identity and the public key of your key pair:
The Fully Qualified Domain Name (FQDN) to secure, e.g. example.com or *.example.com for wildcards.
Legal company name registered with the government. Required for OV and EV business validation.
Two-letter ISO country code (e.g. ID, US, SG). Must match the official registered business address.
Additional hostnames and subdomains secured under a single multi-domain SSL certificate.
RSA 2048-bit (industry baseline) or RSA 4096-bit for long-term cryptographic assurance.
The private key is generated simultaneously and must NEVER be shared or sent across the internet.
openssl req -new -newkey rsa:2048 -nodes -keyout example_com.key -out example_com.csr openssl req -new -newkey rsa:2048 -nodes \
-keyout example_com.key -out example_com.csr \
-subj "/C=ID/ST=DKI Jakarta/L=Jakarta/O=MyCompany/CN=example.com" \
-reqexts SAN -config <(cat /etc/ssl/openssl.cnf <(printf "[SAN]\nsubjectAltName=DNS:example.com,DNS:www.example.com")) certreq -new request.inf example_com.csr Browse our comprehensive catalog of DV, OV, and EV certificates from Sectigo, DigiCert, and GeoTrust with instant issuance and 24/7 technical validation support.
The premier marketplace for seamless SSL certificate issuance, renewal, and website trust management worldwide.
Global Certificate Distribution Hub
Support: support@renewalssl.com
Knowledge Base & Guides
CSR Generator Guide
Contact Support Team
Client Portal Login
View Shopping Cart
Quick Checkout
© 2026 RenewalSSL.com. All rights reserved.
Next-gen PKI platform. Manage digital trust at enterprise scale.
Automate the full certificate lifecycle. Stay secure and compliant.
Simplify certificate lifecycle management across your entire network.
Automate the full certificate lifecycle. Stay secure and compliant.
Protect software supply chains. Ensure secure code delivery.
Digitally sign and validate documents. Preserve integrity and origin.