A certificate request is a file that proves you own a domain and want to secure it with encryption

When you want to add an SSL/TLS certificate to a website, you do not send your private key to the certificate authority. Instead, you create a certificate signing request (CSR) — a file that contains your domain name, your public key, and information about your organization. You keep the private key. The certificate authority uses the CSR to verify you control the domain, then sends back a signed certificate that browsers will trust.

Think of it like proving your identity to get a passport. You do not hand over your birth certificate and social security number to the passport office. You fill out a form (the CSR) that proves who you are, the office verifies it, and they issue you a passport (the certificate). The passport proves to anyone who checks it that you are who you say you are.

A certificate request is a technical step you take yourself or ask your hosting provider to take for you. It is not something a certificate authority creates — you create it, then send it to them.

Key Takeaways

  • A certificate request contains your domain name, public key, and organization details, but not your private key, which you keep secret.
  • You generate the request on your server or through your hosting control panel, then send it to a certificate authority for signing.
  • The certificate authority verifies you control the domain before sending back a signed certificate that browsers will recognize.
  • Most hosting providers can generate the request for you, so you may never see the technical file itself.

What information goes into a certificate request

When you create a CSR, you provide details that the certificate authority needs to issue the right certificate for your domain. The request includes your domain name (the Common Name), your organization name, your location (country, state, city), and your email address. It also includes a public key that was generated at the same time as your private key.

The certificate authority does not need your private key — and you should never send it. The private key stays on your server and is used to decrypt traffic. The public key in the CSR is used by browsers to encrypt traffic to your site. This separation is what makes the system secure.

Different types of certificates require different levels of detail in the request. A basic domain validation certificate (DV) only needs your domain name to be correct. A business validation certificate (OV) or extended validation certificate (EV) requires accurate organization information, which the certificate authority will verify by contacting your business directly.

How to generate a certificate request

If you manage your own server, you generate a CSR using command-line tools. On Linux or macOS, you use OpenSSL. On Windows, you use IIS (Internet Information Services) or a third-party tool. The process creates two files at once: the certificate request file and a private key file. You send the request to the certificate authority and keep the private key safe.

Most people do not do this themselves. Your hosting provider usually has a button in the control panel (cPanel, Plesk, or their own interface) that generates the request for you. You fill in your domain name and organization details, click a button, and the system creates the request and stores the private key on your server automatically.

Some certificate authorities also provide tools that generate the request in your browser, though this is less common because it means the private key is created in your browser rather than on your server.

What happens after you submit a certificate request

Once you send the CSR to a certificate authority, they verify that you control the domain. For a domain validation certificate, this usually means they send you an email to an address listed in the domain's WHOIS record, or they check a DNS record or file you place on your website. You confirm ownership, and they issue the certificate within minutes to a few hours.

For business validation or extended validation certificates, the process takes longer. The certificate authority contacts your organization by phone or email to confirm the details in your request match your real business. This can take a few days.

Once the certificate is issued, you install it on your server alongside the private key that was created when you made the request. The certificate and private key work together — the certificate is public and goes to browsers, the private key stays on your server and never leaves.

Why certificate requests matter for security

The certificate request process exists to prevent someone else from getting a certificate for your domain. If certificate authorities issued certificates without verifying ownership, an attacker could request a certificate for your domain, install it on their server, and intercept traffic meant for your site.

By requiring you to prove you control the domain before issuing a certificate, the system ensures that only you can get a certificate that browsers will trust for your domain. The request itself is not secret — you can share it with your hosting provider or a certificate authority without risk, because it does not contain anything that could be used to decrypt your traffic or impersonate your site.

Certificate requests for different scenarios

If you are moving your website to a new hosting provider, you may need a new certificate request because the private key will be on a different server. You cannot move a private key between servers safely in most cases, so you generate a new request on the new server and get a new certificate issued.

If you are adding a subdomain to your certificate, you may need to request a new certificate that covers both the main domain and the subdomain (a Subject Alternative Name certificate). This requires a new CSR with both domains listed.

If your certificate is expiring, you can reuse the same private key and generate a new request to renew it, or you can generate a new key and request at the same time. Most hosting providers handle renewal automatically and you never see the request.

Common mistakes when working with certificate requests

The most common mistake is sending your private key to the certificate authority. You should never do this. If someone asks for your private key, they are not a legitimate certificate authority. The CSR file is what you send — the private key stays on your server.

Another mistake is losing the private key after you generate the request. If the private key is deleted and you did not back it up, you cannot use the certificate that comes back. You have to generate a new request and get a new certificate issued. This is why hosting providers keep backups of private keys.

A third mistake is putting the wrong domain name in the request. If you request a certificate for example.com but your site is at www.example.com, the certificate will not match and browsers will show a security warning. Most certificate authorities let you add multiple domain names to one request, so check what domains you need before you create the request.

Frequently Asked Questions

Can I use the same certificate request for multiple domains?

No. Each certificate request is tied to one private key on one server. If you want to secure multiple domains, you can request a certificate that covers multiple domains (a wildcard or multi-domain certificate), but you create one request that lists all the domains you want to cover.

What if I lose my certificate request file?

The request file itself is not important after the certificate is issued. You only need the certificate file and the private key. If you need to renew or reissue the certificate, you can generate a new request. The old request can be deleted.

Do I need a new certificate request every time I renew my certificate?

You can renew using the same private key and generate a new request, or you can generate a completely new key and request. Most hosting providers handle renewal automatically and you do not have to do anything. If you are renewing manually, your certificate authority will tell you whether to reuse the key or create a new one.

Can someone use my certificate request to impersonate my website?

No. The request alone cannot be used to impersonate your site. An attacker would need the private key that goes with it, which is not in the request file. The request is safe to share with your hosting provider or certificate authority.