Wait! Don't Leave Without Securing Your Site
Get enterprise - grade SSL certificates at a fraction of retail prices.
Save 10% on your first order, by entering coupon code SAVE10 during checkout.

A CSR decoder is a tool that reads a Certificate Signing Request and displays its contents in plain language. It reverses the Base64 and ASN.1 encoding that makes a CSR unreadable by eye, then labels each field: Common Name, Organization, Organizational Unit, Locality, State, Country, public key algorithm, key size, signature algorithm and any Subject Alternative Names. You would use one to verify a request before submitting it, or to work out why a certificate you already have is behaving unexpectedly.
Copy Link
Paste it into a CSR decoder, sometimes listed as a CSR viewer or CSR reader, and read the labelled output. A CSR looks like a solid block of random characters because it is Base64-encoded binary data, so there is nothing useful to see by opening the file in a text editor. If you prefer the command line, openssl req -in example.csr -noout -text prints the same information.
Copy Link
When generating a CSR for a Wildcard SSL certificate, you must add an asterisk (*) in front of the domain name you want to secure. For example, you would enter *.yourdomain.com in the Common Name field.
Copy Link
The best tool to quickly generate a CSR code is our CSR Generator. All you have to do is enter your details in the required fields for instant CSR generation.
Copy Link
It’s not recommended to use an existing CSR when applying for a new SSL certificate, as re-using the same key over very long periods may compromise website security.
Copy Link
When you generate a CSR via an external tool such as a CSR generator, you should enter one single domain name or sub-domain. The rest of the domains or sub-domains, known as SANs (2nd, 3rd, 4th domains or sub-domains), should be included in the fields for additional domains. You will find the additional domain fields on the SSL Certificate configuration form.
If you generate the CSR with OpenSSL, you need to create a new file named req.conf and add more DNS entries. Here’s the command line to request the CSR:
openssl req -new -out request_name.csr -newkey rsa:2048 -nodes -sha256 -keyout request_name.key -config req.conf
Copy Link
To generate the CSR on your server, you need access to your control panel or secure shell terminal. You can also create the CSR externally via a CSR generator tool directly from your browser.
Copy Link
The system or platform on which you generate the CSR will create two text files. The file with the .csr extension will contain your CSR code, while the file with the .key extension will include your private key.
Copy Link
The CSR generation itself is instant. The only time you’ll spend is filling in the required CSR fields with your contact information.
Copy Link
You must generate a CSR code every time you apply for a new certificate or are renewing your expiring cert. The CA uses the up-to-date data from your CSR to validate and issue your SSL certificate.
Copy Link