Certificates & Proofs / PKI Workshop
What you will do: Work through five steps: generate a CSR, create a Root CA, issue a certificate by signing the CSR with that CA, parse the certificate, then build a CRL.
Worked example: Generate a CSR for example.com with a new RSA 2048-bit key, self-sign a Root CA, press Sign Certificate to issue the leaf, then Parse Details shows its subject and issuer.
Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.
For your role
- Developer / Engineer
- Step 1 generates a key and a CSR (choose the key source and a profile), Step 2 creates a root CA, Step 3 issues the certificate, Step 4 parses it and Step 5 revokes it with a CRL: the Console Output is the OpenSSL you would run.
- Security Architect
- Pick a profile in Select Profile and read the constraints it applies, then compare the parsed certificate in Step 4: the fields and sizes are what a PQC key changes in a chain.
- Researcher / Academic
- Use the Console Output at each step to reproduce the CSR, CA, issuance and CRL outside the browser.
- IT Ops / DevOps
- Run the five steps once with the default RSA key to see the full issue-and-revoke cycle, then note the Step 5 CRL: it is the artefact your revocation distribution has to carry.
- Curious Explorer
- Follow the five steps in order: you make a request, create an authority, get a certificate issued, read what is inside it, and revoke it — the whole life of a certificate in one sitting.
Step 1: Generate CSR
Create a Certificate Signing Request using a key pair.
01|KEY CONFIGURATION
Generate new keypair • Select algorithm • Choose key size
02|SELECT PROFILE
Load industry template • Apply standards • Set constraints
Without a profile the CSR will contain only the Subject DN — no extensions (SAN, EKU, keyUsage). Modern CAs require a subjectAltName per CAB Forum BR. Select a profile to inject the correct extensions for your use case.
3BUILD CSR ATTRIBUTES
Define Subject DN • Add Extensions • Configure Request
| Use | Type | Name | Value | Rec. / Desc. |
|---|---|---|---|---|
| SubjectRDN | Common Name Mandatory | The fully qualified domain name (FQDN) of your server. | ||
| SubjectRDN | Organization | Legal name of the organisation requesting the certificate. | ||
| SubjectRDN | Country | Two-letter ISO 3166-1 country code of the organisation. |
subjectAltName (SAN) extension per CAB Forum Baseline Requirements. The CN alone has been deprecated for TLS hostname validation since 2017. Select a profile above to load SAN and other required extensions automatically.4SIGN & CREATE CSR
Hash request data • Sign with private key • Encode to PEM
Console Output
Next in sequence
Cert Capacity Calculator
Model the storage, bandwidth, and CPU impact of migrating your PKI to ML-DSA at scale.
Try it
After Step 3 issues the certificate, what does Step 5 produce for the Root CA?
Next step
Turn it into a plan: Infrastructure Modernization PlannerThis tool practises the PKI module, phase 6 (Infrastructure & Performance); Infrastructure Modernization Planner produces a deliverable of that phase.
Related content
Next in Certificates & Proofs