What is a certificate signing request?
A certificate signing request, or CSR, is a PKCS#10 structure containing a public key and identifying subject fields, signed by the corresponding private key. A certificate authority uses it as the input for issuing a certificate while the private key remains with the requester.
The generator creates a 2048-bit RSA key and SHA-256-signed PEM CSR locally with node-forge. Common name is required, while organization and two-letter country are optional. Review every field before submission and back up the private key securely; a CA cannot recover it if it is lost.