↑ ↓ select, Enter open, Esc close

Generate a private key and CSR for multiple domains

Caution: This command changes the system. Understand what it does before you run it.

Adjust the values, the command updates live
user@server
openssl req -new -newkey rsa:2048 -nodes -keyout example.com.key -out example.com.csr -subj "/CN=example.com" -addext "subjectAltName=DNS:example.com,DNS:www.example.com"

Creates an unencrypted 2048-bit RSA key and a CSR in the current directory, ready to submit to a certificate authority. -addext adds the domain and its www variant as Subject Alternative Names, which is mandatory today. Afterwards, store the key so that only root can read it.

Note: Existing files with the same name are overwritten without asking. -addext requires OpenSSL 1.1.1 or newer.

Also searched as

  • generate csr with subject alternative names
  • openssl create key and csr one command
  • create certificate signing request linux
  • csr with www and non-www

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.