ECC CSR Assistant & PKI Decoder Hybrid

Generate clean ECC CSR command paths for Windows and Linux first. The wider PKI Decoder now sits under the Decoder tab, so certificate analysis remains available without displacing the main CSR workflow.

Environment health score
--
Generate a result to assess the environment.
ECC: P-384
Hash: SHA-256
Hybrid Cloudflare
Quick posture
No result yet

Environment and server stack

The assistant remains the front door. Use it to shape the CSR request and produce the right script path before moving into certificate analysis.

ECC CSR request details

Comma-separated DNS names and IP entries. Use prefixes like IP:192.0.2.10 when needed. CN is added automatically if missing.

Generated output

ImportantThis page gives script output and guidance only. Run the script on the target server or on an approved admin workstation.

Decoder

The assistant stays as the main workflow. The PKI Decoder and SSL Checker live here as subordinate analysis tools.

This path uses a Cloudflare Pages Function with node TLS compatibility enabled.

Post-Deployment Validation

Immediate validation

    Certificate and chain

      Service-specific checks

        Close-out actions

          Built-in knowledge bank

          ECC profile

          • P-384 / secp384r1 / SHA-256
          • PowerShell + certreq for Windows
          • OpenSSL path for Linux

          Decoder scope

          • Certificates
          • CSRs
          • PKCS#7 and CMS
          • CRLs and SSL hostname checking

          Why this layout changed

          The CSR assistant now leads the page because the core purpose is to help the operator produce the right request script before anything else.
          The broader PKI decoder remains present, but it now supports the main workflow rather than competing with it.
          Local decode protects pasted material. Edge mode and SSL checking keep the Cloudflare server-side route ready for live certificate inspection.