Generate X.509 certificates, CSRs
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-04-07 18:06:22 +02:00
rcgen chore: sync dependencies (monorepo) 2026-04-07 18:06:22 +02:00
rustls-cert-gen chore: sync dependencies (monorepo) 2026-04-06 20:09:30 +02:00
verify-tests Add testing of CSR Params parsing Basic Constraints variants 2026-03-27 07:59:20 +00:00
.gitignore Updated .gitignore to be more specific 2025-05-19 12:12:23 +02:00
.rustfmt.toml Group imports by module 2025-10-13 08:59:57 +00:00
.rustfmt.unstable.toml Group imports by module 2025-10-13 08:59:57 +00:00
Cargo.lock chore: sync dependencies (monorepo) 2026-04-07 18:06:22 +02:00
Cargo.toml chore: sync dependencies (monorepo) 2026-04-06 20:42:15 +02:00
LICENSE update copyright year in LICENSE 2026-01-19 06:39:12 +00:00
README.md chore: sync dependencies (monorepo) 2026-04-06 20:42:15 +02:00

rcgen

Simple Rust library to generate X.509 certificates.

use rcgen::{generate_simple_self_signed, CertifiedKey};
// Generate a certificate that's valid for "localhost" and "hello.world.example"
let subject_alt_names = vec!["hello.world.example".to_string(),
	"localhost".to_string()];

let CertifiedKey { cert, key_pair } = generate_simple_self_signed(subject_alt_names).unwrap();
println!("{}", cert.pem());
println!("{}", key_pair.serialize_pem());

Trying it out with openssl

You can do this:

cargo run
openssl x509 -in certs/cert.pem -text -noout

For debugging, pasting the PEM formatted text to this service is very useful.

Trying it out with quinn

You can use rcgen together with the quinn crate. The whole set of commands is:

cargo run
cd ../quinn
cargo run --example server -- --cert ../rcgen/certs/cert.pem --key ../rcgen/certs/key.pem ./
cargo run --example client -- --ca ../rcgen/certs/cert.der https://localhost:4433/README.md

MSRV

The MSRV policy is to strive for supporting 7-month old Rust versions.

License

This crate is distributed under the terms of both the MIT license and the Apache License (Version 2.0), at your option.

See LICENSE for details.

License of your contributions

Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.