How to Generate Certificate Signing Request (CSR) in MAC OS X 10.5


This document provides instructions how to generate a CSR for Apple Mac OS X Server 10.5. If you can not perform this steps on the server, please conatct Apple Support.

NOTE: To generate a CSR, a key pair must be created for the server. These two items are a digital certificate key pair and cannot be separated. If the public/private key file or password is lost or changed before the SSL certificate is installed, the SSL certificate will need to be re-issued. The private key, CSR, and certificate must all match in order for the installation to be successful.
NOTE: Using the Server Admin utility to create certificate requests for new certificates and renewals is not recommended, as it can lead to issues when installing the new SSL certificate.

To generate a Certificate Signing Request (CSR) file using Apple Mac OS X Server 10.5, perform the following steps:

1.    Launch the Server Admin tool and connect to the server where you want to install the certificate.
2.    Highlight the server node in the SERVERS list.
3.    Select the Certificates button from the toolbar at the top of the right pane:

4.    Click the button.

5.    Fill in the fields as appropriate. A brief description of each field follows:

Common Name - The fully-qualified domain name for which you plan to use your certificate (e.g., - "").

Organization - The full legal name of your organization. The listed organization must be the legal registrant of the domain name in the certificate request.

Organizational Unit (Optional) - Enter the name of a business unit or group. If applicable, you may enter the DBA (doing business as) name in this field.

City (Locality) - Name of the city in which your organization is registered/located. Please spell out the name of the city. NOTE: Do not abbreviate.

State/Province - Name of state or province where your organization is located. Please enter the full name. NOTE: Do not abbreviate.

Country Code - The two-letter International Organization for Standardization (ISO) format country code for the country in which your organization is legally registered.

Valid From/Expires On -Not used. Leave at default values.

Private Key Size - Must be at least 2048bit.

Private Key Passphrase (Optional) - If you wish to use a private key passphrase, enter and confirm it here. Note that this passphrase will need to be made available to the system whenever starting any applications that make use of this certificate. If you want your services to be able to start automatically upon server startup, leave the passphrase field blank.  

6.    Click the Done button, then click the Save button. Click the "Gear" button and then select Generate Certificate Signing Request

7.    Drag the icon on the sheet to the directory where you wish to save the certificate request. 

       The rest of this document assumes that the file was saved to the Desktop.

8.    Click Done.

9.    Rename the file that was created from "-----BEGIN CERTIFICATE----- & -----END CERTIFICATE-----" to "certreq." This file contains the Certificate Signing Request (CSR) that you will need to provide when submitting your certificate request to RapidSSL.

10.    You can close the Server Admin application.

11.    Verify your CSR

12.    Proceed with the Enrolment.




WarungSSL has made efforts to ensure the accuracy and completeness of the information in this document. However, WarungSSL makes no warranties of any kind (whether express, implied or statutory) with respect to the information contained herein. WarungSSL assumes no liability to any party for any loss or damage (whether direct or indirect) caused by any errors, omissions, or statements of any kind contained in this document.

Further, WarungSSL assumes no liability arising from the application or use of the product or service described herein and specifically disclaims any representation that the products or services described herein do not infringe upon any existing or future intellectual property rights. Nothing herein grants the reader any license to make, use, or sell equipment or products constructed in accordance with this document. Finally, all rights and privileges related to any intellectual property right described herein are vested in the patent, trademark, or service mark owner, and no other person may exercise such rights without express permission, authority, or license secured from the patent, trademark, or service mark owner. Geotrust reserves the right to make changes to any information herein without further notice.


We uses cookies to remember and process the items in your shopping cart as well as to compile aggregate data about site traffic and interactions so that we can continue improving your experience on our site.