Certificates & Proofs / PKI Workshop

What you will do: Work through five steps: generate a CSR, create a Root CA, issue a certificate by signing the CSR with that CA, parse the certificate, then build a CRL.

Worked example: Generate a CSR for example.com with a new RSA 2048-bit key, self-sign a Root CA, press Sign Certificate to issue the leaf, then Parse Details shows its subject and issuer.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools · Learn with PKI

For your role

Developer / Engineer
Step 1 generates a key and a CSR (choose the key source and a profile), Step 2 creates a root CA, Step 3 issues the certificate, Step 4 parses it and Step 5 revokes it with a CRL: the Console Output is the OpenSSL you would run.
Security Architect
Pick a profile in Select Profile and read the constraints it applies, then compare the parsed certificate in Step 4: the fields and sizes are what a PQC key changes in a chain.
Researcher / Academic
Use the Console Output at each step to reproduce the CSR, CA, issuance and CRL outside the browser.
IT Ops / DevOps
Run the five steps once with the default RSA key to see the full issue-and-revoke cycle, then note the Step 5 CRL: it is the artefact your revocation distribution has to carry.
Curious Explorer
Follow the five steps in order: you make a request, create an authority, get a certificate issued, read what is inside it, and revoke it — the whole life of a certificate in one sitting.

Step 1: Generate CSR

Create a Certificate Signing Request using a key pair.

01|KEY CONFIGURATION

Generate new keypair • Select algorithm • Choose key size

Private Key Source:

02|SELECT PROFILE

Load industry template • Apply standards • Set constraints

CSR Profile

Without a profile the CSR will contain only the Subject DN — no extensions (SAN, EKU, keyUsage). Modern CAs require a subjectAltName per CAB Forum BR. Select a profile to inject the correct extensions for your use case.

3BUILD CSR ATTRIBUTES

Define Subject DN • Add Extensions • Configure Request

UseTypeNameValueRec. / Desc.
SubjectRDN
Common Name
Mandatory
The fully qualified domain name (FQDN) of your server.
SubjectRDN
Organization
Legal name of the organisation requesting the certificate.
SubjectRDN
Country
Two-letter ISO 3166-1 country code of the organisation.
No SAN loaded. Modern TLS certificates require a subjectAltName (SAN) extension per CAB Forum Baseline Requirements. The CN alone has been deprecated for TLS hostname validation since 2017. Select a profile above to load SAN and other required extensions automatically.

4SIGN & CREATE CSR

Hash request data • Sign with private key • Encode to PEM

Console Output

Next in sequence

Cert Capacity Calculator

Model the storage, bandwidth, and CPU impact of migrating your PKI to ML-DSA at scale.

Try it

After Step 3 issues the certificate, what does Step 5 produce for the Root CA?

Next step

Turn it into a plan: Infrastructure Modernization Planner

This tool practises the PKI module, phase 6 (Infrastructure & Performance); Infrastructure Modernization Planner produces a deliverable of that phase.

Next in Certificates & Proofs