Generate a CA-Signed Certificate

Get a certificate signed by the getaCert Certificate Authority. Useful for testing CA trust chains.

Already have a CSR? Sign an existing Certificate Signing Request

  1. Domain
  2. Identity
  3. Options
  4. Review
What domain or hostname is this certificate for?
Enter a fully qualified domain name (e.g. www.example.com) or use *.example.com for wildcard.
The CN is automatically included as a SAN. Add extra DNS names or an IP address here.
Organization details (all optional, improves certificate subject)
Certificate options
Signed by the current getaCert root. This is the root offered on the CA certificate page and the one to use unless you already have an older getaCert root installed.
Signed by the original getaCert root (serial 07B2, valid 2004-01-07 to 2031-05-08). Pick this only if the systems that must trust the certificate already have that root installed. The same CA was re-issued in 2016 with a SHA-256 signature and a 2038 expiry, and one certificate validates under either root, so install whichever of the two your systems accept.
RSA 2048 — Industry standard. Maximum compatibility with all browsers, servers, and devices. Good default choice.
RSA 4096 — Stronger RSA key. Required by some government and compliance standards (FIPS, NIST). Larger file size.
ECDSA P-256 — Elliptic curve. Much smaller keys and faster TLS handshakes. Widely supported in modern browsers.
ECDSA P-384 — Stronger elliptic curve. Required for CNSA suite compliance. Good balance of security and performance.
Ed25519 — Edwards curve. Smallest keys and fastest signing. Cutting-edge; not yet supported by all software.
Free Certificates up to 30 days are free.
— Requires a one-time purchase via Stripe. You'll be redirected after clicking Generate.
Review your certificate details
Please fix the following before generating:
Common Name
SANs
Organization
Department
Email
Country
State / Province
City
Key Type
Signing CA Legacy root
Expiration Paid Free
Password password (for private key and PKCS#12)
Certificates longer than 30 days require a one-time purchase (). You'll be securely redirected to Stripe to complete payment, then your certificate will be generated automatically.