Collection of Tools

Generate a complete certificate chain (Root CA, Intermediate CA, Server) with custom DNS and IP SANs. All keys are generated client-side and never leave your browser.

Settings

1. Root CA

2. Intermediate CA

3. Server Certificate

Quick Presets
Subject Alternative Names (SANs)
dns localhost ip 127.0.0.1
Configure settings above and click "Generate Certificate Chain" to create certificates
About Certificate Generator: Generate self-signed certificate chains for development, testing, and internal PKI. Supports RSA and ECDSA key algorithms with configurable validity periods. All cryptographic operations use the Web Crypto API and run entirely in your browser — private keys are never transmitted anywhere. Add the Root CA to your system trust store to avoid browser warnings during local development.