Paste a PEM certificate signing request (the block starting with —–BEGIN CERTIFICATE REQUEST—–) to confirm it contains the right names and a strong key before ordering a certificate. The CSR is parsed entirely in your browser.
Table of Contents
What to check before submitting
The Subject Alternative Names list must contain every host name the certificate should cover, including the bare domain and www if you need both; public CAs ignore the Common Name if it is not also a SAN. RSA keys should be at least 2048 bits (3072 for long-lived certificates) or use ECDSA P-256. The signature should be SHA-256 or stronger.
Create a CSR with SAN names on the command line: openssl req -new -newkey rsa:2048 -nodes -keyout example.key -out example.csr -subj “/CN=example.com” -addext “subjectAltName=DNS:example.com,DNS:www.example.com”
CSR decoder at a glance



Official documentation: cPanel & WHM documentation, AlmaLinux wiki, Linux man pages.
Related guides: CVE-2026-65638, 65639 and 67402 explained: patching the CSF Messenger and URLGET remote-code flaws · CrowdSec vs Imunify360 vs BitNinja: choosing a post-CSF security stack for shared hosting · KernelCare on cPanel and DirectAdmin servers: setup, verification and rollback.
Frequently asked questions
Is it safe to paste my CSR here?
Yes. A CSR contains only public information, and this tool does not send it anywhere. Never paste the private key into online tools; use our key matcher, which also runs locally.
Where does cPanel store the CSR?
In cPanel go to SSL/TLS → Certificate Signing Requests; WHM uses Generate an SSL Certificate and Signing Request. Both show the PEM text you can paste here.
Why is my Common Name missing?
Many modern tools create CSRs with only SAN names. That is fine; CAs issue from the SAN list.