When you buy an SSL certificate from a Certificate Authority (CA), the first thing it asks for is a Certificate Signing Request, or CSR. A CSR is a block of encoded text. It contains your domain name, your organisation details and your location, and the CA uses it to issue your certificate.
When the CSR is made, a matching private key is made too. You need that key later to install the certificate. Without it, the certificate is useless.
Using the free SSL included with FimuroHost Cloud Hosting? You don't need a CSR. This guide is only for third-party certificates.
Information you'll need
| Field | Example |
|---|---|
| Common Name (domain) | www.example.com. For a wildcard, *.example.com |
| Organisation | Your registered business name |
| Organisational Unit / Department | e.g. IT (optional for many CAs) |
| City / Locality | Dhaka |
| State / Province | Dhaka |
| Country (2-letter code) | BD |
For Organisation Validated (OV) or Extended Validation (EV) certificates, the organisation details must exactly match your official company records.
Option 1: Use an online CSR generator
- Open an online CSR generator such as https://csrgenerator.com. Many CAs also provide one in their order form.
- Fill in the fields above and generate the CSR.
- Copy both blocks it shows: the CSR (
BEGIN CERTIFICATE REQUEST) and the private key (BEGIN PRIVATE KEY). - Save each one in a plain-text file on your computer.
Option 2: Use OpenSSL on your own computer
This way, the private key never leaves your machine. OpenSSL comes with macOS and Linux, and on Windows with Git for Windows or WSL. Run:
openssl req -new -newkey rsa:2048 -nodes \ -keyout example.com.key -out example.com.csr
Answer the questions as they come up. You will end up with two files: example.com.csr, which you send to the CA, and example.com.key, the private key you keep.
Next steps
- Paste the CSR into your certificate order and complete the CA's validation.
- When the certificate is issued, install it with the private key and CA bundle. See "Install a Third-Party SSL Certificate in StackCP".
Tips
- Keep the CSR and private key. Store them somewhere safe, such as a password manager or an encrypted folder. If you lose the key, you have to generate a new CSR and ask for the certificate to be reissued.
- Never share the private key publicly or send it by plain email.
- The certificate usually covers both the main domain and the www version. Check with your CA if you need extra names.
Need help?
If something doesn't work as described, open a support ticket from your FimuroHost client area or message us on WhatsApp at 01818160926. Please include your domain name so we can check your account quickly.
Categories
Written by
FimuroHost Team
Technical Writer