GlobalSign Security Solutions Secure SSL Certificates  |  Home  |  Contact Us    
Search Technical Support & FAQs  
 
Certificates SSL menu divider Enterprise Solutions SSL menu divider Partners SSL menu divider Customer Support SSL menu divider About GlobalSign

 

 


Customer Support > SSL Certificates > Certificate Signing Request Generation - ApacheSSL / Apache+OpenSSL - KB1004

To generate a Certificate Signing Request (CSR), perform the following steps:


Generating the Key Pair

1. The utility "OpenSSL" is used to generate both Private Key (key) and Certificate Signing request (CSR). OpenSSL is usually installed under /usr/local/ssl/bin. If you have a custom install, you will need to adjust these instructions appropriately.

2. Type the following command at the prompt:

openssl genrsa –des3 –out www.mydomain.com.key 1024

Note: If you do not wish to use a Pass Phrase, do not use the -des3 command. It will however leave the private key unprotected.

3. Enter the PEM Pass Phrase (This MUST be remembered)

a

4. This will generate a 1024 RSA Private key, and stores it in the file www.mydomain.com.key.


Generating the CSR

1. Type the following command at the prompt:

openssl req –new –key www.mydomain.com.key –out www.mydomain.com.csr

Note: You will be prompted for the PEM Pass Phrase if you included the "-des3" command. Type it in now.

c

NOTE: There is a known issue with Apache/OpenSSL Windows Based Installations. If you recevie an error with the above command, Please enter the following:
openssl req -new -key www.mydomain.com.key -out www.mydomain.com.csr -config openssl.cnf

2. Input the information for the Certificate Signing Request. This information will be displayed in the certificate.

Note: The following characters can not be accepted: < > ~ ! @ # $ % ^ * / \ ( ) ?.,&

Country Name (2 letter code) [AU]:GB
State or Province Name (full name) [Some-State]:London
Locality Name (eg, city) []:London
Organization Name (eg, company) [Internet Widgits Pty Ltd]:Global Sign
Organizational Unit Name (eg, section) []:IT
Common Name (eg, YOUR name) []:www.globalsign.net (Must be the FQDN - Fully Qualifed Domain Name)

Note: DO NOT Enter the following:

Email Address []:
A challenge password []:
An optional company name []:

d

3. Please verify the CSR, to insure all information is correct. Use the following command:

openssl req -noout -text -in www.mydomain.com.csr

4. The CSR will now be created, and can be submitted via the website.

 

   
  SSL Certificate Supported Browsers
GlobalSign Inc (a member of GMO Internet Inc group TSE:9449) offers online security services and has been operating as a
trusted Root Certification Authority
for over 10 years. GlobalSign Certificates are trusted by all popular Browsers,
Operating Systems, Devices and Applications and include SSL, SSL Certificates, Extended SSL Certificates, Code Signing,
Personal Digital IDs
, Enterprise Digital IDs, internal PKI & Microsoft CA root signing.