You can create your own SSL certificate for a local server without paying a certificate authority
A self-signed certificate is an SSL certificate you generate yourself on your computer or server, rather than buying one from a certificate authority like Let's Encrypt or DigiCert. Your browser will show a security warning when you visit a site using a self-signed certificate, because the browser cannot verify that a trusted third party vouched for the certificate. This is normal and expected — self-signed certificates work fine for development, testing, and internal networks where you control all the machines connecting to the server.
The process takes 10 to 15 minutes and requires only command-line tools that come built into Windows, Mac, and Linux. You do not need special software or an internet connection to a certificate authority. The certificate you create will work immediately on your local server.
Key Takeaways
- Self-signed certificates are free and work on local servers, but browsers will show a security warning because no trusted authority verified them.
- On Mac and Linux, use the OpenSSL command-line tool to generate a certificate and private key in one step.
- On Windows, you can use OpenSSL (installed via Git Bash or WSL), or use PowerShell's built-in New-SelfSignedCertificate command.
- After creating the certificate, you must configure your server software to use the certificate file and private key file.
- Add the certificate to your browser's trusted store to stop the security warning, or accept the warning each time you visit during development.
Generate a certificate on Mac or Linux with OpenSSL
OpenSSL is a command-line tool that comes pre-installed on Mac and Linux. Open your terminal and run this single command to create both a certificate and a private key:
openssl req -x509 -newkey rsa:4096 -keyout private.key -out certificate.crt -days 365 -nodes
The command will prompt you for information: country code (US), state, city, organization name, and common name. For the common name, enter the hostname or IP address of your local server — for example, localhost or 192.168.1.100. This is the name you will type into your browser's address bar. You can press Enter to skip any field except common name.
The command creates two files in your current directory: certificate.crt (the certificate) and private.key (the private key). The -days 365 flag makes the certificate valid for one year; change this number if you want it to last longer. Keep both files in a safe location — your server needs both to enable HTTPS.
Generate a certificate on Windows with PowerShell
Windows 10 and later include PowerShell, which has a built-in command to create self-signed certificates. Open PowerShell as Administrator (right-click PowerShell and select "Run as administrator") and run this command:
New-SelfSignedCertificate -CertStoreLocation Cert:\CurrentUser\My -DnsName localhost -FriendlyName "Local Server" -NotAfter (Get-Date).AddYears(1)
Replace localhost with the hostname or IP address your server will use. The certificate is automatically stored in Windows' certificate store, not as a file on disk. If you need the certificate as a file (most server software does), you must export it. Open the Certificate Manager by typing certmgr.msc in the Run dialog, find your certificate under "Personal" → "Certificates", right-click it, select "All Tasks" → "Export", and save it as a .pfx file with a password.
Alternatively, if you have Git Bash or Windows Subsystem for Linux (WSL) installed, you can use the OpenSSL command from the Mac and Linux section above.
Configure your server to use the certificate
After creating the certificate and private key, you must tell your server software where to find them. The exact steps depend on what server you are running — Node.js, Python, Apache, Nginx, or something else.
For a Node.js server, create a file called server.js (or edit your existing server file) to load the certificate and key:
const https = require('https'); const fs = require('fs'); const app = require('./app'); const options = { key: fs.readFileSync('./private.key'), cert: fs.readFileSync('./certificate.crt') }; https.createServer(options, app).listen(443);
For Python with Flask, use the ssl_context parameter:
app.run(ssl_context=('certificate.crt', 'private.key'), host='localhost', port=443)
For Apache, add these lines to your virtual host configuration file:
SSLEngine on SSLCertificateFile /path/to/certificate.crt SSLCertificateKeyFile /path/to/private.key
For Nginx, add these lines to your server block:
listen 443 ssl; ssl_certificate /path/to/certificate.crt; ssl_certificate_key /path/to/private.key;
Restart your server after making these changes. Your server should now accept HTTPS connections on port 443 (or whatever port you configured).
Handle the browser security warning
When you visit your local server in a browser, you will see a warning that says the connection is not secure or that the certificate is not trusted. This happens because your certificate is self-signed — no certificate authority verified it. The warning is expected and does not mean something is wrong.
You have two options. First, you can simply accept the warning each time you visit during development. Click "Advanced" or "More Information" and then "Proceed" or "Visit this site anyway". Your connection is still encrypted; the warning only means the browser cannot verify who issued the certificate.
Second, you can add the certificate to your browser's trusted store so the warning stops appearing. On Mac, open Keychain Access, drag your certificate.crt file into the window, find it in the list, double-click it, expand "Trust", and set "When using this certificate" to "Always Trust". On Windows, double-click the certificate file, click "Install Certificate", choose "Current User", and select "Place all certificates in the following store" → "Trusted Root Certification Authorities". On Linux, the process varies by browser and distribution — Firefox has its own certificate store separate from the system, while Chrome uses the system store.
Renew or replace your certificate
Self-signed certificates expire after the number of days you specified when creating them (365 days by default). When your certificate expires, your browser will show a warning that the certificate is no longer valid. You cannot renew a self-signed certificate — you must create a new one.
Before your certificate expires, run the OpenSSL or PowerShell command again to generate a new certificate and private key. Use the same common name (hostname or IP address) so you do not have to change your server configuration. Update your server to point to the new certificate and key files, then restart the server.
If you added the old certificate to your browser's trusted store, you will need to add the new one as well. Delete the old certificate from your trusted store first to avoid confusion.
Frequently Asked Questions
Can I use a self-signed certificate on the public internet?
Technically yes, but you should not. Browsers will show a security warning to every visitor, which damages trust and looks unprofessional. For public websites, use a free certificate from Let's Encrypt or another certificate authority. Self-signed certificates are meant for development, testing, and internal networks only.
What is the difference between a certificate and a private key?
The certificate is the public part — you can share it or put it on a website. The private key is secret — it must stay on your server and never be shared. Together they enable encryption: the certificate encrypts data sent to your server, and the private key decrypts it. If someone gets your private key, they can impersonate your server.
Do I need a certificate for every server I run?
Yes, each server needs its own certificate and private key. You can create multiple certificates with different common names (one for localhost, one for 192.168.1.100, one for myserver.local) and use whichever one matches the address you are visiting.
Can I use a self-signed certificate with a domain name instead of localhost?
Yes. When you run the OpenSSL command, enter your domain name (like myserver.local) as the common name instead of localhost. Your server must be accessible at that domain name on your network — this usually requires editing your hosts file or setting up a local DNS server. For most development work, localhost is simpler.
What if I lose my private key file?
You cannot recover it. You must create a new certificate and private key, update your server configuration, and restart the server. This is why you should keep backups of both files in a safe location.