Sunday, October 4, 2026
GovTech & Cybersecurity Standards Benchmark
Global Digital Verification
✕
Public Key Infrastructure (PKI) • 2026 Reference Peer Reviewed

How to Generate and Audit CSR (Certificate Signing Request) via OpenSSL

Single-command OpenSSL generation of 2048/4096-bit RSA and ECDSA CSRs with Subject Alternative Names (SAN), and cryptographic modulus verification.

WebOTG Standards Directorate
11 mins
Oct 06, 2026
0 views
Advertisement

1. Executive Summary: What is a Certificate Signing Request (CSR)?

A Certificate Signing Request (CSR) is a block of encoded text sent to a Certificate Authority (CA) to apply for an SSL/TLS digital certificate. It contains your organization's verified domain names, public key, and identity information, signed using your corresponding private key.

Under modern CA/Browser Forum baselines and NIST guidelines, all CSRs must use minimum RSA 2048-bit (or ECDSA P-256/P-384) keys and must explicitly include domain names in the Subject Alternative Name (SAN) extension.

Standard Specification
PKCS#10 (Certification Request Standard) • RFC 2986 • CA/Browser Forum Baseline Requirements

2. Generating CSR & Private Key via OpenSSL CLI

A. Recommended: Single-Command CSR Generation with SAN (RSA 2048/4096)

This command generates both the private key and CSR in a single non-interactive step, embedding multiple SAN domains:

# Generate 2048-bit RSA private key and CSR with SAN extension openssl req -new -newkey rsa:2048 -nodes \ -keyout target-domain.key \ -out target-domain.csr \ -subj "/C=IN/ST=Delhi/L=New Delhi/O=Department of Electronics/OU=NIC/CN=target-domain.gov" \ -addext "subjectAltName = DNS:target-domain.gov, DNS:www.target-domain.gov, DNS:api.target-domain.gov" # Secure private key file permissions immediately chmod 600 target-domain.key

B. Modern Elliptic Curve (ECDSA P-256) Generation

# 1. Generate EC parameters and private key openssl ecparam -name prime256v1 -genkey -noout -out target-domain-ec.key # 2. Generate CSR from existing EC key openssl req -new -key target-domain-ec.key \ -out target-domain-ec.csr \ -subj "/C=IN/ST=Uttar Pradesh/L=Lucknow/O=State Governance/CN=target-domain.gov" \ -addext "subjectAltName = DNS:target-domain.gov, DNS:www.target-domain.gov"

3. Inspecting & Decoding CSR Metadata

Before submitting a CSR to DigiCert, Sectigo, or Let's Encrypt, verify that the attributes, public key size, and signature are intact:

# Decode CSR contents and verify internal self-signature openssl req -in target-domain.csr -text -noout -verify # Verification checks in output: # 1. verify OK: Confirms private key signed the CSR cleanly # 2. Public Key Algorithm: rsaEncryption (2048 bit or 4096 bit) # 3. Requested Extensions -> X509v3 Subject Alternative Name: DNS:target-domain.gov

Critical Pre-Deployment Check: Private Key Matching

A common deployment failure is having a CSR that does not match the private key on the server. Verify that the cryptographic moduli match:

# Compute MD5/SHA256 modulus hash of the private key openssl rsa -noout -modulus -in target-domain.key | openssl sha256 # Compute MD5/SHA256 modulus hash of the CSR openssl req -noout -modulus -in target-domain.csr | openssl sha256 # PASS CRITERIA: Both sha256 hashes MUST be completely identical!

4. CSR Audit & Compliance Checklist

Audit Check Standard Requirement Pass Criteria
Key Length RSA ≥ 2048 bits or ECDSA ≥ 256 bits Zero 1024-bit RSA keys generated
SAN Presence All active domains explicitly enumerated in subjectAltName Both apex and www subdomains covered
Signature Algorithm SHA-256 or SHA-384 signature hash Zero MD5 / SHA-1 digest algorithms used
Private Key Security Permissions set to 600 (read/write only by root/owner) Private key never transmitted across unencrypted email or tickets
Advertisement
WE
WebOTG Standards Directorate
PKI Technical Specialist

WebOTG provides benchmark reference documentation, automated matrix evaluators, and security test harnesses for government digital platforms, WQMS architectures, and STQC compliance frameworks.