Wait! Don't Leave Without Securing Your Site
Get enterprise - grade SSL certificates at a fraction of retail prices.
Save 10% on your first order, by entering coupon code SAVE10 during checkout.

Yes. This tool generates both and displays them on this page. Your key pair is created on SSL Dragon’s servers and delivered to your browser, so save both files right away and move the private key onto the server that will use it. If you need the key created on your own machine instead, generate the CSR locally with OpenSSL. Your private key should never be sent to a Certificate Authority.
Copy Link
PKCS#10 is the standard that defines the CSR format, specified in RFC 2986. It sets out which fields a certification request contains and how they are structured, which is why the same CSR works with any Certificate Authority rather than being tied to the one you bought from.
Copy Link
Because it is no longer allowed. CA/Browser Forum ballot SC47 prohibited the Organizational Unit field in publicly trusted TLS certificates issued on or after 1 September 2022, on the grounds that a CA has no reliable way to verify a department name. You can still include OU when you generate a CSR, and the decoder will show it, but the CA strips it before issuing. Nothing has gone wrong.
Copy Link
A Subject Alternative Name is an extension that lists every hostname a certificate covers. Modern browsers read the SAN list and ignore the Common Name entirely, so a domain that appears only as the Common Name and not in the SAN list will fail. Most public CAs copy the Common Name into the SAN list automatically when they issue, but confirm this with your CA rather than relying on it. If you need several hostnames on one certificate, list all of them.
Copy Link
A domain validated certificate confirms only that the applicant controls the domain. An organization validated certificate adds a check on the registered business behind it, including name, address, and registration details, and takes a business day or two rather than minutes. Encryption is identical; the difference is what the certificate says about who runs the site.
Copy Link
Three methods are accepted: a DNS record containing a value the CA supplies, a file uploaded to /.well-known/pki-validation/ on your server, or a link emailed to one of five approved addresses at the domain. DNS and HTTP are the durable options. Email-based validation is being retired by the CA/Browser Forum under ballot SC-090 in March 2028.
Copy Link
Not in this tool. Create a PFX here first, then import it with keytool from the Java JDK. Modern Tomcat also reads PKCS#12 directly, so you may not need a JKS at all.
Copy Link
Yes. DV, OV, EV, wildcard, and multi-domain certificates share the same X.509 structure, so they all convert the same way. Validation level changes what the certificate authority verifies, not the file format.
Copy Link
All three usually hold PEM text, though a .cer can occasionally be DER binary instead. Encoding matters more than the extension, so check the BEGIN/END lines or let the tool detect it.
Copy Link
Only when you’re creating a PFX or PKCS#12 file. If you’ve lost the password to an existing PFX, its key cannot be recovered, and reissuing the certificate is the only fix.
Copy Link