A CSR is a request file that tells a certificate authority who you are
A Certificate Signing Request (CSR) is a block of text that your web server generates and sends to a certificate authority when you want to buy an SSL certificate. It contains information about your website — your domain name, your organization name, your location — and a unique mathematical key that only your server knows. The certificate authority uses this information to verify you own the domain, then sends back a signed certificate that your server and browsers can use to encrypt traffic.
You cannot skip the CSR step. Every SSL certificate starts with one. When you order a certificate from a provider like Sectigo, DigiCert, or Let's Encrypt, you either generate the CSR yourself on your server or the provider generates it for you. Either way, the CSR is what proves to the certificate authority that the request is coming from someone who controls the server.
The CSR itself is not secret and does not need to be kept private. What matters is the private key that your server generated alongside it — that key never leaves your server and never goes to the certificate authority. The certificate authority signs the CSR with its own key, and that signature is what makes the certificate valid.
Key Takeaways
- A CSR contains your domain name, organization details, and a public key that your server generates, and you send it to a certificate authority to request an SSL certificate.
- The private key that pairs with the CSR stays on your server and is never sent anywhere — it is what actually decrypts the traffic.
- You generate a CSR on your server using a command or your hosting control panel, then copy and paste it into your certificate provider's order form.
- If you lose the private key that goes with your CSR, you cannot use the certificate even if you still have the signed certificate file.
- Different server software (Apache, Nginx, Windows IIS) uses different commands to generate a CSR, but the process and the result are the same.
What information goes into a CSR
When your server creates a CSR, it asks you for several pieces of information. The most important is your domain name — this is what the certificate authority will verify you own. You also provide your organization name, your city and state, and your country. Some fields are required; others are optional depending on the type of certificate you are ordering.
The CSR also includes a public key — a long string of characters that your server generates automatically. This public key is mathematically linked to a private key that stays on your server. When someone visits your website, their browser receives the public key from your certificate. Their browser uses that public key to encrypt data, and only your server's private key can decrypt it. The certificate authority never sees or stores your private key.
You can view what is inside a CSR by pasting it into an online CSR decoder, but you cannot edit it once it is generated. If you need to change the domain name or organization name, you have to generate a new CSR.
How to generate a CSR on your server
The steps depend on what software your server runs. If you use Apache or Nginx on Linux, you use the OpenSSL command line tool. If you use Windows Server with IIS, you use the IIS Manager interface. If your website is hosted with a provider like GoDaddy, Bluehost, or Kinsta, your hosting control panel usually has a button to generate a CSR without touching the command line.
For Apache or Nginx, the command looks like this: you run a single OpenSSL command that asks for your domain, organization, and location, then generates two files — the CSR file and a private key file. You keep the private key file safe on your server and never share it. You copy the entire CSR file (it starts with -----BEGIN CERTIFICATE REQUEST----- and ends with -----END CERTIFICATE REQUEST-----) and paste it into your certificate provider's order form.
For IIS on Windows, you open IIS Manager, right-click your website, and select the option to create a certificate request. IIS walks you through the same questions and generates the CSR and private key automatically. You then copy the CSR text and submit it to your certificate provider.
If you use a hosting control panel, look for a section called SSL, Certificates, or Security. Most panels have a one-click button to generate a CSR. The panel stores the private key on your server automatically, so you do not have to manage it yourself.
What happens after you submit your CSR
Once you paste your CSR into your certificate provider's order form and pay, the provider verifies that you own the domain. For a basic Domain Validated (DV) certificate, this usually means they send you an email at an address associated with the domain, or they check a DNS record you add to your domain. This process takes anywhere from a few minutes to a few hours.
After verification, the certificate authority signs your CSR with its own private key and sends you back a signed certificate file. This file is what you install on your server. Your server now has three pieces: the signed certificate, the private key that was generated with the CSR, and the CSR itself (which you can delete once the certificate arrives).
The signed certificate is valid only with the private key that was generated alongside the CSR. If you lose the private key, you cannot use the certificate even if you still have the certificate file. This is why hosting providers back up your private key — if you lose it, they can restore it, but if they lose it, you have to generate a new CSR and order a new certificate.
CSR vs. the certificate itself
The CSR is a request. The certificate is the response. You generate the CSR once, send it to the certificate authority, and then you never need to generate that same CSR again. The certificate that comes back is what you actually install and use.
If you need to renew your certificate when it expires, you can either reuse the same CSR and private key (if your domain and organization details have not changed) or generate a new CSR. Most people generate a new CSR for each renewal to keep things clean, but reusing is technically allowed.
If you move your website to a different server, you need the private key that goes with your certificate. You cannot regenerate it from the certificate alone. This is why you should always keep a backup of your private key file, or make sure your hosting provider backs it up for you.
Common mistakes when working with CSRs
The most common mistake is generating a CSR with the wrong domain name. If you type your domain as example.com but your website is actually www.example.com, the certificate will not match and browsers will show a security warning. Always double-check the domain name before you generate the CSR.
Another mistake is losing the private key. Once you generate a CSR, your server creates a private key file. If you delete this file or your server crashes and the file is not backed up, you cannot decrypt traffic even with the certificate. Always make sure your hosting provider backs up your private key, or keep a copy in a safe place.
A third mistake is generating multiple CSRs for the same certificate order. Some people generate a CSR, submit it, then generate another one and submit that too. This creates confusion and can cause the certificate authority to issue multiple certificates. Generate one CSR per order and stick with it.
Finally, do not share your CSR with anyone except your certificate provider. While the CSR itself is not secret, sharing it means someone else has the information about your domain and organization. Keep it between you and the certificate authority.
Frequently Asked Questions
Can I use the same CSR for multiple certificates?
No. Each CSR is tied to a specific private key on a specific server. If you need a certificate for a different domain or a different server, you have to generate a new CSR. You can reuse a CSR for renewal if your domain and organization details have not changed, but that is the only exception.
What if I generate a CSR but never submit it?
The CSR itself expires after a certain time (usually 30 days), but the private key that was generated with it stays on your server. If you decide to order a certificate later, you can generate a new CSR. The old private key will just sit there unused, which is fine.
Can I view my CSR after I submit it?
Yes. If you saved a copy of the CSR file on your server, you can view it anytime. You can also paste it into an online CSR decoder to see what information it contains. The certificate authority does not send the CSR back to you, so if you did not save a copy, you cannot retrieve it.
What if my certificate provider generates the CSR for me?
Some providers offer to generate the CSR on their servers instead of you generating it on yours. This is convenient but means the private key is created and stored on their servers, not yours. You have to trust them to keep it safe and to give it to you if you move your website. Most people prefer to generate the CSR themselves so they control the private key.
Do I need a new CSR every time my certificate renews?
No, but most people generate a new one anyway. If your domain and organization details have not changed, you can reuse the same CSR and private key. However, generating a new CSR for each renewal is cleaner and reduces the risk of using an old private key that might have been compromised.