FAQs

How to Generate a CSR in Web Host Manager (WHM)

Overview

By the end of this article you will have generated a Certificate Signing Request (CSR) in Web Host Manager (WHM) and submitted it to Sectigo to continue certificate issuance. The article explains what a CSR is, lists the prerequisites, then walks through the procedure: signing in to WHM, opening the SSL/TLS Manager, completing the certificate request form, copying the generated Signing Request block, and pasting it into your Sectigo account. It also covers how to verify the CSR was created, common issues such as the browser privacy warning on the WHM login page, and answers to frequently asked questions.

What is a CSR?

A Certificate Signing Request (CSR) is an encoded block of text that contains the domain name, organization details, and public key that a Certificate Authority (CA) uses to issue an SSL/TLS certificate. When Web Host Manager (WHM) generates a CSR, it also creates the matching private key, which stays on your server and is never sent to the CA.

Prerequisites

  • Root or reseller-level access to the Web Host Manager (WHM) interface
  • The WHM username and password for that account
  • The fully qualified domain name (FQDN) the certificate will secure
  • Organization details required by the request form, such as company name, city, state, and country
  • An active Sectigo account with a certificate order awaiting a Certificate Signing Request (CSR)

Steps to Generate a CSR in WHM

Step 1 — Sign in to Web Host Manager

Open your Web Host Manager (WHM) login page. It is typically reached at https://domain.com:2087, where domain.com is your own domain. Enter your username and password, then select Log in. The WHM Home page is displayed.

 
Figure 1:
WHM login page with username and password fields

Your browser may show "Your connection is not private" or a similar warning on this page. This happens because the WHM login page uses a self-signed certificate by default. Proceed past the warning to reach the login form.

Step 2 — Open the SSL/TLS Manager

On the WHM Home page, select SSL/TLS. The SSL/TLS Manager page opens and lists the certificate tools available in the account.

 
Figure 2:
WHM Home page showing the main administration menu
 

Figure 3: SSL/TLS button on the WHM Home page menu

Step 3 — Open the Certificate Request Form

In the SSL/TLS Manager page, select Generate an SSL Certificate and Signing Request. The Request Form opens.
 

Figure 4: SSL/TLS Manager page with the Generate an SSL Certificate and Signing Request option

Step 4 — Complete the Request Form

Enter the domain name and organization details in the Request Form, then select Create. Web Host Manager (WHM) generates the Certificate Signing Request (CSR) and saves it in your user directory.

Two points to note before selecting Create:

  • Do not send the private key by email or over any other insecure channel. The private key must remain on the server.
  • If 2,048 bits (Recommended) is selected as the Key Size, WHM automatically generates the matching private key. If you already have a private key you want to use, open the Key Size dropdown and select the option that matches that key.

 

Figure 5: Request Form with domain, organization, and Key Size fields

Step 5 — Copy the Signing Request

After generation, select the text inside the Signing Request box and copy all of it, including the first and last lines:

-----BEGIN CERTIFICATE REQUEST-----
-----END CERTIFICATE REQUEST-----

Both boundary lines are part of the Certificate Signing Request (CSR). A request submitted without them is rejected.

Figure 6: Signing Request box displaying the generated CSR text

Step 6 — Submit the CSR to Sectigo

Sign in to your Sectigo account and open the certificate order. Select Provide CSR on our website, paste the entire Certificate Signing Request (CSR) into the text box, and continue through the remaining order steps to complete the request.

How to Verify the CSR Was Created Successfully

The Certificate Signing Request (CSR) was created successfully when all of the following are true:

  • The Signing Request box in Web Host Manager (WHM) displays a block of text beginning with -----BEGIN CERTIFICATE REQUEST----- and ending with -----END CERTIFICATE REQUEST-----.
  • The saved request appears in your user directory on the server.
  • Your Sectigo account accepts the pasted request and moves the order to the next stage without a format error.

Troubleshooting

Issue: "Your connection is not private" appears when opening the WHM login page.

Cause: The Web Host Manager (WHM) login page uses a self-signed certificate by default.

Solution: Proceed past the browser warning to reach the login form. This warning does not affect Certificate Signing Request (CSR) generation.

Issue: Sectigo rejects the pasted Certificate Signing Request (CSR) as invalid.

Cause: The copied text is incomplete — most often the -----BEGIN CERTIFICATE REQUEST----- or -----END CERTIFICATE REQUEST----- line was left out, or extra spaces or line breaks were introduced.

Solution: Return to the Signing Request box in Web Host Manager (WHM), copy the full block including both boundary lines, and paste it again.

Tips and Best Practices

  • Keep the private key on the server. Never send it by email or share it over an unencrypted channel.
  • Use 2,048 bits or higher as the Key Size unless a specific system requires a different value.
  • Confirm the domain name in the Request Form matches the name the certificate must secure before selecting Create. A mismatch requires generating a new Certificate Signing Request (CSR).

Frequently Asked Questions

What is a CSR?

A Certificate Signing Request (CSR) is an encoded block of text containing the domain name, organization details, and public key that a Certificate Authority (CA) uses to issue an SSL/TLS certificate.

Where is the CSR saved in WHM?

Web Host Manager (WHM) saves the generated Certificate Signing Request (CSR) in your user directory on the server. The text is also displayed in the Signing Request box immediately after generation.

Does WHM create the private key as well?

Yes. If 2,048 bits (Recommended) is selected as the Key Size, WHM generates the matching private key automatically. If you already have a private key, select the corresponding option from the Key Size dropdown.

Why does my browser warn me before I reach the WHM login page?

The Web Host Manager (WHM) login page uses a self-signed certificate by default, which browsers do not trust. Proceed past the warning to reach the login form.

Do I need to include the BEGIN and END lines when submitting the CSR?

Yes. Copy the full block, including -----BEGIN CERTIFICATE REQUEST----- and -----END CERTIFICATE REQUEST-----. Submissions missing either line are rejected.

Similar Questions

  • How do I generate a CSR in WHM?
  • What are the steps to create a certificate signing request in Web Host Manager?
  • WHM CSR generation
  • Where do I paste my CSR in my Sectigo account?

Need assistance?

Contact our team for help with your purchase or issuing your certificate.

Live chat

Call us today