Skip to main content

Sign from a CA

Issue a certificate signed by an existing CA: new key pair or CSR, leaf or intermediate CA, with a ready-to-use fullchain.

1. Certificate authority

CA certificate

Decoded in this page. Nothing you paste leaves it.

CA private key (unencrypted PKCS#8)

Decoded in this page. Nothing you paste leaves it.

The test CA is a P-256 key pair generated in this page, valid ten years, for trying the tool. It is stored nowhere and dies with the tab; never issue anything real with it.

2. Subject

Load the CA first (step 1).

youkyi_

PKI-Toolbox, a self-hosted PKI decoder. 100% client-side, no data ever leaves your browser.

youkyi.fr github © 2026 · Agasseau Alexandre