openssl req -newkey rsa:4096 …

OpenSSL CSR & Self-Signed Commands

Compose copy-ready openssl shells backed by sane defaults, use Lets Encrypt or an internal PKI for Internet-facing workloads.

DNS hostnames, one per line. DNS: is added unless you paste IP:127.0.0.1 style entries.

Production warning

Trusted browsers need a public CA unless you explicitly install roots. Stick to homelab gateways, smoke tests and developer TLS here.

Linux openssl csr and SAN certificate helper

openssl req one-liners for CSRs (-new) versus throwaway crt files (-x509) with quoting-friendly -subj and subjectAltName -addext for OpenSSL 1.1.1 and newer releases.

OpenSSL builder FAQ

Which OpenSSL versions support inline -addext SAN lines?

OpenSSL 1.1.1 and later accept -addext for subjectAltName. Older stacks need a patched openssl.cnf snippet instead.

Why does Ed25519 produce two shells?

Ed25519 still begins with openssl genpkey so the csr or x509 step cleanly reuses -key afterwards across versions.

Do I keep the passphrase empty?

-nodes skips encrypting keys at rest which is simplest for unattended services. Omit -nodes plus add interactive prompts whenever you encrypt keys on disk.