A certificate signing request, or CSR, contains a public key and information needed to request a certificate. It is created with a matching private key. Keep that private key on the server where the certificate will be installed. The website's SSL order form asks for the CSR, never the private key.
These steps apply to a paid SSL order. Control Center's free Request Let’s Encrypt SSL workflow handles its own request and does not use this order form.
- Open the intended domain in Virtualmin. In Manage Virtual Server → Setup SSL Certificate, use Create Signing Request if your account provides it. Follow the panel's fields and retain the corresponding private key securely. Preserve any existing working certificate and key before changes. Virtualmin commercial certificate setup
- Set the request name to match the order. A wildcard order needs
*.example.comin its CSR even though you enteredexample.comduring purchase. Do not add unrelated domain names. If the hosting panel cannot generate the required request, ask support for assistance. - Copy the complete PEM CSR, including its beginning and ending lines. Do not copy a certificate or a block labeled private key into this field.
- Sign in to the website, open My Account → Orders, view the SSL order, and paste the request into CSR (PEM).
- Choose Approval email from the addresses offered by the registrar. Confirm that you can receive messages at the chosen address, then select Submit SSL configuration. A made-up address or an arbitrary replacement cannot be used.
- Follow the issuer's approval email. Complete any additional organization checks required for OV or EV. If Open registrar SSL setup is shown, it is an optional registrar-provided route; follow the instructions associated with that order.
- Return to the order and select Refresh status after completing validation.
Check the result: The order should move from configuration to validation and eventually show issuance when the certificate has been verified. Keep the private key paired with this request available for installation.
Common problems: CSR rejection can mean malformed PEM, a wrong domain, or a key/request mismatch. Missing approval choices require support. Check Spam and mailbox routing for a missing approval email. Do not submit repeated configurations after an uncertain outcome or buy another certificate to bypass manual review.
Related: Purchase SSL, Install the issued certificate, Reissue.


Leave a Reply