Issue a certificate

CA & profile → attributes → extensions & issuedemo
A client-side Next/Back wizard over one unified form — hidden steps stay in the DOM so the single submit carries everything. Submit shows a toast in this mirror. Back to landing
1CA & profile
2Attributes
3Extensions & issue

Issuer & profile

Key & validity

External CSR (optional)

Upload a CSR to use an externally generated key pair. Leave empty to generate the key server-side.

Subject

Subject Alternative Names

Key Usage (OID 2.5.29.15)

Extended Key Usage (OID 2.5.29.37)

Distribution-point overrides (blank = inherit from issuing CA)

Subject / Authority Key Identifiers

Custom OID values

Add ad-hoc OIDs to embed as critical or non-critical extensions. Each row becomes one openssl line.

Extra openssl extension lines

Raw openssl.cnf extension lines, one per line. Used verbatim in the extfile.

Cancel