Self-Signed Certificate Generator — X.509 v3 for test and internal use
Self-Signed Certificate Generator
This page creates a key pair and signs an X.509 v3 certificate with it, so the
certificate is its own issuer. You get the certificate as
-----BEGIN CERTIFICATE----- and as raw DER, plus the private key as
PKCS#8. It is the right tool for a development server, an internal appliance, a
lab or a mail gateway that you control on both ends — and the wrong tool for
anything a stranger's browser has to trust without a warning.
A self-signed certificate is not trusted by anything.
No public browser, operating system or mail client will accept it until you
install it as a trusted root on every machine that talks to the service. If you
need a certificate that works without installing anything, get one from a
certificate authority — and if you only need a request for a CA, use the
CSR generator instead.
1. Key
RSA 2048 bit, signed with SHA-256.
2. Subject and issuer
The issuer is written as a copy of these fields, which is what makes the certificate
self-signed. The common name is the name shown in certificate dialogs; what the
client actually matches is the subject alternative names below.
3. Subject alternative names
at least one entry is required
One entry per line, with an optional dns:, ip:,
email: or uri: prefix; a bare line is a DNS name, unless
it is an address literal such as 127.0.0.1, which is taken as an IP
address. Since
browsers stopped looking at the common name, a certificate without at least one
subject alternative name is rejected outright, so this page insists on one.
4. Validity and extensions
starts now, ends in 365 days
Anything from 1 to 825 days. Publicly trusted certificates have been limited to
200 days since 15 March 2026 (100 days from 2027, 47 days from 2029), but a
self-signed certificate is not covered by that rule — it is still a good
habit to keep it short, because nothing revokes it for you.
Leave the CA switch off for a server or client certificate. Turning it on makes the
certificate able to sign other certificates, which is how you build an internal
hierarchy — and also how you hand out a key that can impersonate anything your
root trusts, so keep it for a root you are deliberately keeping offline.
Key usage — what this key may be used for:
Extended key usage — the purposes the certificate is issued for:
5. Generate
nothing generated yet
Generating…
Result
Nothing generated yet. Fill in a common name and at least one subject
alternative name, press Generate certificate and key, and the
certificate and the key appear here with buttons to save them.
How to add it to a trust store — every machine that connects to the
service needs this before the warning goes away. Browsers warn on the first use of a
new authority by design, so read what you are trusting before you click through.
Windows (machine wide)
Open the .crt file, choose Install Certificate, select
Local Machine, then Place all certificates in the following store
→ Trusted Root Certification Authorities. From an elevated prompt the
same thing is certutil -addstore -f Root mycert.crt, and
certutil -delstore Root mycert.crt removes it again.
macOS
Double-click the file to add it to the login keychain, then open Keychain Access,
drag it into System, double-click it, open Trust and set
When using this certificate to Always Trust. On the command line:
sudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain mycert.crt.
Debian, Ubuntu
Copy it to /usr/local/share/ca-certificates/mycert.crt (PEM, and the
name must end in .crt), then run sudo update-ca-certificates.
It is removed by deleting the file and running the same command again.
RHEL, Fedora, CentOS
Copy it to /etc/pki/ca-trust/source/anchors/mycert.crt and run
sudo update-ca-trust.
Firefox
Firefox keeps its own store: Settings → Privacy &
Security → Certificates → View Certificates →
Authorities → Import, then tick Trust this CA to
identify websites.
Java applications
Import it into the JDK trust store:
keytool -importcert -alias mycert -file mycert.crt -cacerts -storepass changeit.
What the extensions mean. Basic constraints say whether the
certificate may sign other certificates; key usage restricts the operations the key
may perform; extended key usage names the purposes the certificate is issued for, and
a TLS server certificate needs the TLS server purpose or clients that check
it will refuse. The subject key identifier is a hash of the public key, and the
authority key identifier normally names the issuer's copy of it — on a
self-signed certificate both carry the same value.
What this page does not do: it does not create a certificate
hierarchy for you, does not run a CA, and does not install anything anywhere. There
is no revocation list behind this certificate: if the key leaks, the only remedies
are replacing the file everywhere and removing it from every trust store.
Privacy: the key pair is generated by the browser's own
cryptography and the certificate is signed here. No upload, no server, no cookies,
no analytics, and the page works from a local file. To read the result back
independently, use the certificate decoder.
🔒 SSL & TLS Tools
Certificate and key utilities that run entirely in your browser.