rsa:2048
openssl req -new -newkey rsa:2048 -nodes \
-keyout domain.tld.key \
-out domain.tld.csr \
-subj "/C=TH/ST=Bangkok/O=Organization/OU=IT/CN=www.domain.tld"
-keyout domain.tld.key \
-out domain.tld.csr \
-subj "/C=TH/ST=Bangkok/O=Organization/OU=IT/CN=www.domain.tld"
rsa:2048 with SAN
openssl req -new -newkey rsa:2048 -nodes \
-keyout domain.tld.key \
-out domain.tld.csr \
-subj "/C=TH/ST=Bangkok/O=Organization/OU=IT/CN=www.domain.tld" \
-addext "subjectAltName = DNS:www.domain2.tld,DNS:www.domain3.tld"
-keyout domain.tld.key \
-out domain.tld.csr \
-subj "/C=TH/ST=Bangkok/O=Organization/OU=IT/CN=www.domain.tld" \
-addext "subjectAltName = DNS:www.domain2.tld,DNS:www.domain3.tld"
P-256 (ECC)
openssl req -new -newkey ec:<(openssl ecparam -name prime256v1) -nodes \
-keyout domain.tld.key \
-out domain.tld.csr \
-subj "/C=TH/ST=Bangkok/O=Organization/OU=IT/CN=www.domain.tld
-keyout domain.tld.key \
-out domain.tld.csr \
-subj "/C=TH/ST=Bangkok/O=Organization/OU=IT/CN=www.domain.tld
P-256 (ECC) with SAN
openssl req -new -newkey ec:<(openssl ecparam -name prime256v1) -nodes \
-keyout domain.tld.key \
-out domain.tld.csr \
-subj "/C=TH/ST=Bangkok/O=Organization/OU=IT/CN=www.domain.tld" \
-addext "subjectAltName = DNS:www.domain2.tld,DNS:www.domain3.tld"
-keyout domain.tld.key \
-out domain.tld.csr \
-subj "/C=TH/ST=Bangkok/O=Organization/OU=IT/CN=www.domain.tld" \
-addext "subjectAltName = DNS:www.domain2.tld,DNS:www.domain3.tld"
C = Country Name (2 letter code)
ST = State or Province Name
O = Organization Name
OU = Organizational Unit
CN = Common Name
ST = State or Province Name
O = Organization Name
OU = Organizational Unit
CN = Common Name