OpenSSL CSR & Self-Signed Commands
Compose copy-ready openssl shells backed by sane defaults, use Lets Encrypt or an internal PKI for Internet-facing workloads.
Production warning
Trusted browsers need a public CA unless you explicitly install roots. Stick to homelab gateways, smoke tests and developer TLS here.
Linux openssl csr and SAN certificate helper
openssl req one-liners for CSRs (-new) versus throwaway crt files (-x509) with quoting-friendly -subj and subjectAltName -addext for OpenSSL 1.1.1 and newer releases.
OpenSSL builder FAQ
Which OpenSSL versions support inline -addext SAN lines?
OpenSSL 1.1.1 and later accept -addext for subjectAltName. Older stacks need a patched openssl.cnf snippet instead.
Why does Ed25519 produce two shells?
Ed25519 still begins with openssl genpkey so the csr or x509 step cleanly reuses -key afterwards across versions.
Do I keep the passphrase empty?
-nodes skips encrypting keys at rest which is simplest for unattended services. Omit -nodes plus add interactive prompts whenever you encrypt keys on disk.