# Creating CSR

**URL:** <https://community.zymbit.com/t/creating-csr/1302>\
**Category:** HSM6\
**Created:** [October 29, 2021, 8:27pm UTC](https://community.zymbit.com/t/creating-csr/1302 "2021-10-29T20:27:49Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alberto](https://avatars.discourse-cdn.com/v4/letter/a/ea5d25/32.png) [@Alberto](https://community.zymbit.com/u/Alberto)\
**Post date:** [October 29, 2021, 8:27pm UTC](https://community.zymbit.com/t/creating-csr/1302/1 "2021-10-29T20:27:49Z")

</div>

Hi support team

I`m trying to find out how to create a CSR on HSM6 with **function create\_public\_key\_file()** , please could help us giving a sample of this with input data ( CN, , OU, …) ?

def zymkey.module.Zymkey.create\_public\_key\_file (  
self,  
filename,  
slot = 0,  
foreign = False )  
Create a file with the PEM-formatted public key.  
This method is useful for generating a Certificate Signing Request.

Thanks

---

<div class="post-metadata">

**Author:** ![Bob\_of\_Zymbit](https://avatars.discourse-cdn.com/v4/letter/b/82dd89/32.png) [@Bob\_of\_Zymbit](https://community.zymbit.com/u/Bob_of_Zymbit)\
**Post date:** [November 1, 2021, 4:11pm UTC](https://community.zymbit.com/t/creating-csr/1302/2 "2021-11-01T16:11:13Z")

</div>

To generate a CSR, you don’t need to first export the public key to a file. You can use openssl and include `-engine zymkey_ssl` to use the Zymkey keys. There is an example you can find here:

> [@Generating a Certificate Signing Request (CSR) Using Zymkey](https://community.zymbit.com/t/generating-a-certificate-signing-request-csr-using-zymkey/537):
>
> Zymkey can be used as part of the client side TLS transaction against a server that is configured for mutual authentication. A CSR can be generated using Zymkey. This CSR can be used to generate a certificate from a preferred Certificate Authority or CA (for example: GoDaddy, Comodo or Verisign) or against your own self signed root CA. To generate a CSR with one of Zymkey’s key slots, simply type the following OpenSSL commands on your Raspberry Pi: touch bogus.key openssl req -key bogus.key -…

You can specify an environment variable `ZK_SSL_SLOT` to openssl with the slot you would like to use.

For example, to use ATTEC slot 2,

`ZK_SSL_SLOT=2 openssl req -key bogus.key -new -out myCert.csr -engine zymkey_ssl -keyform e`

This is particularly useful with the HSM6 which allows you to generate up to 512 additional key pairs.
