Self-Signed Certificate Generator

This page creates a key pair and signs an X.509 v3 certificate with it, so the certificate is its own issuer. You get the certificate as -----BEGIN CERTIFICATE----- and as raw DER, plus the private key as PKCS#8. It is the right tool for a development server, an internal appliance, a lab or a mail gateway that you control on both ends — and the wrong tool for anything a stranger's browser has to trust without a warning.
A self-signed certificate is not trusted by anything. No public browser, operating system or mail client will accept it until you install it as a trusted root on every machine that talks to the service. If you need a certificate that works without installing anything, get one from a certificate authority — and if you only need a request for a CA, use the CSR generator instead.
1. Key
RSA 2048 bit, signed with SHA-256.
2. Subject and issuer
The issuer is written as a copy of these fields, which is what makes the certificate self-signed. The common name is the name shown in certificate dialogs; what the client actually matches is the subject alternative names below.
3. Subject alternative names
at least one entry is required
One entry per line, with an optional dns:, ip:, email: or uri: prefix; a bare line is a DNS name, unless it is an address literal such as 127.0.0.1, which is taken as an IP address. Since browsers stopped looking at the common name, a certificate without at least one subject alternative name is rejected outright, so this page insists on one.
4. Validity and extensions
starts now, ends in 365 days
Anything from 1 to 825 days. Publicly trusted certificates have been limited to 200 days since 15 March 2026 (100 days from 2027, 47 days from 2029), but a self-signed certificate is not covered by that rule — it is still a good habit to keep it short, because nothing revokes it for you.
Leave the CA switch off for a server or client certificate. Turning it on makes the certificate able to sign other certificates, which is how you build an internal hierarchy — and also how you hand out a key that can impersonate anything your root trusts, so keep it for a root you are deliberately keeping offline.
Key usage — what this key may be used for:
Extended key usage — the purposes the certificate is issued for:
5. Generate
nothing generated yet
Nothing generated yet. Fill in a common name and at least one subject alternative name, press Generate certificate and key, and the certificate and the key appear here with buttons to save them.
How to add it to a trust store — every machine that connects to the service needs this before the warning goes away. Browsers warn on the first use of a new authority by design, so read what you are trusting before you click through.
Windows (machine wide) Open the .crt file, choose Install Certificate, select Local Machine, then Place all certificates in the following store → Trusted Root Certification Authorities. From an elevated prompt the same thing is certutil -addstore -f Root mycert.crt, and certutil -delstore Root mycert.crt removes it again.
macOS Double-click the file to add it to the login keychain, then open Keychain Access, drag it into System, double-click it, open Trust and set When using this certificate to Always Trust. On the command line: sudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain mycert.crt.
Debian, Ubuntu Copy it to /usr/local/share/ca-certificates/mycert.crt (PEM, and the name must end in .crt), then run sudo update-ca-certificates. It is removed by deleting the file and running the same command again.
RHEL, Fedora, CentOS Copy it to /etc/pki/ca-trust/source/anchors/mycert.crt and run sudo update-ca-trust.
Firefox Firefox keeps its own store: Settings → Privacy & Security → Certificates → View Certificates → Authorities → Import, then tick Trust this CA to identify websites.
Java applications Import it into the JDK trust store: keytool -importcert -alias mycert -file mycert.crt -cacerts -storepass changeit.
What the extensions mean. Basic constraints say whether the certificate may sign other certificates; key usage restricts the operations the key may perform; extended key usage names the purposes the certificate is issued for, and a TLS server certificate needs the TLS server purpose or clients that check it will refuse. The subject key identifier is a hash of the public key, and the authority key identifier normally names the issuer's copy of it — on a self-signed certificate both carry the same value.

What this page does not do: it does not create a certificate hierarchy for you, does not run a CA, and does not install anything anywhere. There is no revocation list behind this certificate: if the key leaks, the only remedies are replacing the file everywhere and removing it from every trust store.

Privacy: the key pair is generated by the browser's own cryptography and the certificate is signed here. No upload, no server, no cookies, no analytics, and the page works from a local file. To read the result back independently, use the certificate decoder.