↑ ↓ select, Enter open, Esc close

Create a self-signed certificate for testing

Caution: This command changes the system. Understand what it does before you run it.

Adjust the values, the command updates live
user@server
openssl req -x509 -newkey rsa:2048 -nodes -days 365 -keyout test.key -out test.crt -subj "/CN=test.example.com" -addext "subjectAltName=DNS:test.example.com"

Generates an unencrypted RSA key and a certificate signed with it, valid for the given number of days. Browsers show a warning for it, but it is good enough for staging servers, internal tools or testing the web server configuration. The SAN entry is required because current browsers no longer accept the common name alone.

Note: Existing files with the same name are overwritten. For public websites, always use a certificate from a real CA.

Also searched as

  • create self signed certificate openssl
  • generate test ssl certificate
  • ssl certificate for localhost
  • openssl self signed cert one liner

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.