A CSR is the form you fill out to request an SSL certificate
A Certificate Signing Request (CSR) is a block of encrypted text that you generate on your server and send to a certificate authority (CA) — the organization that issues SSL certificates. Think of it like a passport application: you fill out information about yourself and your website, encrypt it, and submit it to an official body that verifies you and issues the credential.
The CSR contains details about your website: your domain name, your organization's legal name, your location, and a public encryption key that the CA will use to create your certificate. You generate the CSR using tools built into your web server software — most commonly OpenSSL, a free encryption tool that runs on Linux, Windows, and Mac servers.
You never send your private key (the secret half of your encryption pair) to the CA. The CSR only contains the public key. This matters because your private key stays on your server and never leaves — it's what actually decrypts the traffic that arrives encrypted from visitors' browsers.
An SSL certificate proves your website is who it claims to be
An SSL certificate is a digital credential issued by a certificate authority that tells visitors' browsers: "Yes, this website really belongs to the organization that claims to own it." When you visit a website with HTTPS (the secure version of HTTP), your browser checks that website's SSL certificate before it establishes an encrypted connection.
The certificate contains your domain name, your organization's details, the public key from your CSR, and a digital signature from the CA proving the CA verified your identity. When a visitor's browser arrives at your site, it reads the certificate and checks: Does the domain in the certificate match the domain in the address bar? Is the CA's signature valid? Has the certificate expired? If all three checks pass, the browser shows a padlock icon and establishes an encrypted connection.
Without an SSL certificate, browsers display a "Not Secure" warning. Visitors see this warning and often leave — they have no way to know whether they're talking to your real website or an imposter intercepting their traffic.
Key Takeaways
- A CSR is the encrypted request form you generate on your server and send to a certificate authority to request an SSL certificate.
- An SSL certificate is the credential the CA issues back to you, which proves to visitors that your website is legitimate and enables encrypted connections.
- Your private key never leaves your server — the CSR only contains your public key, which the CA uses to create the certificate.
- Visitors' browsers check your SSL certificate before connecting, and display a "Not Secure" warning if the certificate is missing, invalid, or expired.
- Most web hosting providers and domain registrars can generate your CSR and handle the certificate request process for you if you don't want to do it manually.
How the CSR and certificate work together
The CSR is the input; the SSL certificate is the output. You create the CSR on your server using a command-line tool or your hosting control panel. The CSR contains your website's information and a public encryption key. You copy the CSR text and paste it into the CA's order form, along with proof that you own the domain (usually by adding a DNS record or receiving an email to an admin address).
The CA verifies your identity and ownership, then uses the public key in your CSR to create your SSL certificate. The CA signs the certificate with its own private key — this signature is what makes the certificate trustworthy. The CA sends the certificate back to you, and you install it on your server alongside your private key.
From that point forward, when a visitor arrives at your website, their browser receives your SSL certificate, checks the CA's signature, and if everything is valid, encrypts all traffic between the browser and your server using the public key from the certificate. Your server decrypts that traffic using the private key that never left your server.
Different types of SSL certificates for different needs
Certificate authorities issue different types of SSL certificates depending on how much verification they perform and how many domains the certificate covers. A Domain Validated (DV) certificate requires only proof that you own the domain — the CA sends you an email or asks you to add a DNS record. DV certificates are the cheapest and fastest to obtain, usually issued within minutes or hours. They work for any website, but they don't prove anything about the organization behind the domain.
An Organization Validated (OV) certificate requires the CA to verify your organization's legal existence and that you have authority to request the certificate. This takes a few days and costs more, but the certificate displays your organization's name in the browser's certificate details. Visitors see that a real business is behind the website.
A Wildcard certificate covers your main domain and all subdomains (like mail.example.com, shop.example.com, and blog.example.com) with a single certificate. A multi-domain certificate (also called a SAN certificate) covers multiple unrelated domains with one certificate. Both cost more than a single-domain certificate but save money if you run multiple sites.
How to get a CSR and SSL certificate
If you use a web hosting provider, they usually handle CSR generation and certificate installation for you. You log into your hosting control panel, navigate to the SSL section, and either purchase a certificate directly or paste in a CSR you've generated. Many hosting providers offer free DV certificates through Let's Encrypt, a nonprofit CA that automates the entire process.
If you want to generate a CSR manually, you use OpenSSL on a Linux server or a Windows equivalent like Git Bash. The command is: openssl req -new -newkey rsa:2048 -nodes -keyout private.key -out request.csr. This generates two files: your private key (which you keep secret and install on your server) and your CSR (which you send to the CA). On Windows servers running IIS, you use the IIS Manager interface to generate a CSR instead.
Once you have your certificate from the CA, you install it on your server by uploading the certificate file and pointing your web server software to it. The exact steps depend on your server software — Apache, Nginx, and IIS all have different installation procedures — but your hosting provider or the CA usually provides step-by-step instructions.
What happens when an SSL certificate expires
SSL certificates have expiration dates, typically one year or three years from the issue date. When a certificate expires, browsers stop trusting it and display a "Not Secure" warning, even though the certificate itself is still valid cryptographically. Visitors see the warning and often leave.
Before your certificate expires, you request a new one by generating a new CSR and submitting it to the CA (or to your hosting provider if they manage it for you). Many hosting providers send reminder emails 30, 14, and 7 days before expiration. Some providers automatically renew certificates if you've set up auto-renewal, so you don't have to remember.
The renewal process is the same as the initial request: generate a new CSR, submit it to the CA, prove you own the domain, and install the new certificate. You can renew a certificate at any time before it expires, and the new certificate's expiration date starts from the renewal date, not the original issue date.
Frequently Asked Questions
Do I need a different CSR for each SSL certificate?
Yes. Each time you request a new certificate — whether it's your first certificate, a renewal, or a certificate for a different domain — you generate a new CSR. The CSR is tied to the private key on your server, and each private key should be unique. If you lose your private key, you generate a new CSR and request a new certificate.
What if I move my website to a different server?
You can move your SSL certificate to a new server by exporting both the certificate and the private key from your old server and importing them into your new server. The exact steps depend on your server software, but most hosting providers can do this for you. You don't need to request a new certificate unless your domain name changes.
Can I see what's in someone else's SSL certificate?
Yes. Your browser stores a copy of every SSL certificate it receives. You can click the padlock icon in the address bar and view the certificate details, including the domain, organization name, issue date, and expiration date. This is how you verify that a website's certificate is legitimate before entering sensitive information.
What's the difference between HTTP and HTTPS?
HTTP is unencrypted — anyone on your network can see what data you're sending to a website. HTTPS uses an SSL certificate to encrypt that data so only your browser and the website's server can read it. HTTPS requires an SSL certificate; HTTP does not.
Is a free SSL certificate as secure as a paid one?
Yes, in terms of encryption strength. A free DV certificate from Let's Encrypt encrypts traffic just as securely as a paid OV certificate. The difference is verification: a paid OV certificate proves the organization behind the domain is real, while a free DV certificate only proves domain ownership. For most websites, a free certificate is sufficient.