OpenSSL on Linux: Generate Private Keys, CSR and Self-Signed Certificates

openssl generate certificate linux - custom-ssl-featured.png

Before Let's Encrypt automation, every admin learned openssl commands for keys and CSRs. You still need them for internal services, load balancer uploads, and understanding what Certbot creates behind the scenes.

For public websites use Certbot on Nginx; use OpenSSL directly for lab and private PKI.

Key, CSR, Certificate

The private key stays on the server. The CSR is sent to a CA (or you self-sign). The certificate is the public file clients trust.

TLS files
key csr cert

Self-Signed Certificate (Lab)

Quick HTTPS for dev — browsers will warn until you trust the cert.

bashone-liner
openssl req -x509 -newkey rsa:2048 -nodes -keyout key.pem -out cert.pem -days 365 -subj "/CN=dev.local"
self-signed
x509

Generate Key and CSR Separately

Commercial CAs and some cloud load balancers want a CSR while you keep the key.

bashkey + csr
openssl genrsa -out server.key 2048
openssl req -new -key server.key -out server.csr
CSR
req -new

File Permissions

Private keys must not be world-readable.

bashsecure key
chmod 600 server.key
chown root:root server.key
permissions
600

Inspect and Test

Check expiry before outages bite.

bashinspect
openssl x509 -in cert.pem -noout -dates
openssl s_client -connect localhost:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -dates
x509 and s_client
expiry

Renewal in Production

Automate public certs — do not manually re-run openssl every 90 days.

NoteAfter renew, reload Nginx: sudo systemctl reload nginx.
renewal
certbot

Hostname Mismatch

Certificate SAN/CN must match the URL clients use.

name mismatch
SNI

Quick Reference

  • Production HTTPS: Certbot for public sites
  • Keys: chmod 600
  • Check expiry with openssl x509 -dates

Related tutorials

Diagrams are original illustrations by Gnome IT Solutions. Tutorial text © Gnome IT Solutions.