What is a CSR
A CSR (Certificate Signing Request) is the request you submit to a certificate authority to have an SSL certificate issued. It contains the domains, organization details and the public key. A private key is created along with the CSR — it stays with you and is installed on the server together with the issued certificate.
Which key to choose
- RSA 2048 — compatible with everything, the standard for most sites.
- RSA 4096 — a longer key; connections are established slightly more slowly.
- ECDSA P-256 — modern, fast and as strong as RSA 3072. Supported by all current browsers.
Security
The key is generated in memory on our server, sent to you over a secure connection and not stored. For maximum security, run the openssl command shown directly on your server — then the key never leaves it. You can check the finished request with the CSR decoder.