CACrown ArchivesThe cinema collection
Menu
Research dossier · General Reference

Certificate signing request

message from an applicant to a certificate authority to apply for a digital identity certificate; lists the public key the certificate should be issued for, identifying information (e.g. domain name) and integrity protection (e.g. digital signature)

Cross-disciplinary reference desk with index cards, atlas, dictionary and catalogue
General referenceInterpretive dossier study · Crown Archives visual atlas
Record originEnglish Wikipedia
Text licenseCC BY-SA 4.0
Source revisionMar 5, 2026
Entity authorityQ627554
Source-derived summary

In public key infrastructure (PKI) systems, a certificate signing request (CSR or certification request) is a message sent from an applicant to a certificate authority of the public key infrastructure (PKI) in order to apply for a digital identity certificate. The CSR usually contains the public key for which the certificate should be issued, identifying information (such as a holder or domain name) and a proof of possession of the corresponding private key (typically in the form of a digital signature, which includes integrity protection). The most common format for CSRs is the PKCS #10 specification, first published in November 1993; others include the more capable Certificate Request Message Format (CRMF) and the SPKAC (Signed Public Key and Challenge) format generated by some web browsers.

Note that neither of the CSR formats authenticate the identity of the requester. The proof of origin of the request must be achieved and verified by other means (typically using a certificate enrollment protocol such as CMP, EST, or ACME), otherwise the obtained certificate has no real security value.

Procedure

Before creating a CSR for an X.509 certificate, the applicant generates a key pair, keeping the private key of that pair secret, e.g.:

The CSR contains information identifying the applicant (such as a distinguished name), the public key chosen by the applicant, and possibly further information. When using the PKCS #10 format, the request must be self-signed using the applicant's private key, which provides proof of possession (POP) of the private key but limits the use of this format to keys that can be used for (some form of) signing.

The CSR must be accompanied by a proof of origin (i.e., proof of identity of the applicant), which is required for security reasons by the certificate authority. The certificate authority may contact the applicant for further information.

Typical information required in a CSR (sample column from sample X.509 certificate).

Editorial summary

“Certificate signing request” enters the record as message from an applicant to a certificate authority to apply for a digital identity certificate; lists the public key the certificate should be issued for, identifying information (e.g. domain name) and integrity protection (e.g. digital signature). Crown Archives preserves that source wording while asking what Certificate, signing and request can confirm, complicate or overturn.

Editorial reviewA practical starting point whose main value is the path it opens into stronger specialist and primary sources. The current lead gives the account dated anchors—1993—that can be checked directly. The selected authority fields contribute no independent date. Its strongest next move is a source search built around Certificate, signing and request.
Editorial analysis

Why this record matters

“Certificate signing request” is worth following because a concise public description often conceals a longer documentary argument. Here, Certificate, signing and request provides the most credible route into that argument.

Evidence profile

Named sources, stable identifiers and responsible institutions provide the strongest route from overview to verifiable evidence. The source revision retrieved here is dated Mar 5, 2026. The linked authority identifier is Q627554. None of the 0 selected statements returned an explicit reference. The first chronological checks are 1993.

Critical limits

Overview language is designed for orientation and should not be treated as a substitute for the evidence cited beneath it. The source lead contains qualifying language; that uncertainty should survive quotation, summary and reuse. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.

How to read it

Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.

Best used for
  • Subject orientation
  • Search vocabulary
  • Locating named sources
Verify next

The closest primary source, responsible institution and strongest cited specialist reference.

Three-step research path

  1. Establish the record: confirm the title “Certificate signing request”, its source revision and the description used here.
  2. Expand the search: follow Certificate signing request primary sources, Certificate signing request archive and Certificate research across catalogues and specialist indexes.
  3. Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.

Questions for further research

  1. Which source most directly establishes the central claim about “Certificate signing request”?
  2. Which cited source is closest to the event, object or claim?
  3. Which institution is responsible for the underlying evidence?
Subject index

Search terms from this dossier

Source & attribution

This entry incorporates text from Certificate signing request” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.