Generate Hybrid X509 Certificate

This tool generates an X509 certificate using either a certificate signing request (CSR) or a generated key pair (primary and alternate). The CSR file can be DER or PEM encoded. When generating a key pair the private key and certificate are combined in a ZIP file for download. The alternate public key is included as a SubjectAltPublicKeyInfo extension. The subject DN and/or requested extensions in the CSR file may be used or new ones can be defined.

The certificate can be self-signed or signed by another. If an alternate signing key is used the signature algorithm and value are included as AltSignature extensions. A certificate chain can be created by generating a self-signed root CA certificate, generating any intermediate CA certificates which are signed by the root, and then generating end-entity certificates signed by the intermediate CA.


Subject Public Keys:




Subject DN:


Type Value

Extensions:


Standard Extensions

Name Critical Value

Custom Extensions

OID Critical ASN.1 DER Encoded Data
* only decimals and numeric values allowed
* only decimals and numeric values allowed

Validity Dates:

Dates should be entered in Greenwich Mean Time (GMT). The time will be set to 12 am of the day selected. If needed, an example of a GMT converter can be found here.

Signer:

Warning: private keys uploaded to this tool for digital signature encryption should ONLY be used for test and development purposes.










Cookie Consent Policy

This website uses cookies. See Privacy Policy
Accept