Create a Certificate Signing Request (CSR) in WatchGuard Cloud

Applies To: Cloud-managed Fireboxes

Some of the features described in this topic are only available to participants in the WatchGuard Beta program. If a feature described in this topic is not available in your version of Fireware, it is a beta-only feature.

Use a certificate signing request (CSR) to obtain a signed certificate from a Certificate Authority (CA).

You can generate a CSR from WatchGuard Cloud for your Firebox and submit it to a Certificate Authority (CA) to obtain a signed certificate. You can also use the Let's Encrypt service to request a certificate from WatchGuard Cloud.

Standard CSR requests are available at both the account and device levels in WatchGuard Cloud. The Let's Encrypt certificate service is available only through Device Configuration > Device Certificates for cloud-managed Fireboxes.

Your operator role determines what you can see and do in WatchGuard Cloud. Your role must have Account Administration permissions to view or configure this feature. For more information, go to Manage WatchGuard Cloud Operators and Roles.

CSRs created for your account can only be imported at account level. CSRs created for a device can only be imported at device level.

Create a Certificate Signing Request (CSR)

You can create a standard CSR at the account or device level in WatchGuard Cloud.

To create a CSR for your account, go to Administration > Certificates. To create a CSR for a cloud-managed device, select the device and go to Device Configuration > Device Certificates.

To create a CSR:

  1. Select the CSR tab.
  2. Click Create CSR.

Screenshot of the CSR tab on the Certificates page

  1. On the Specify Subject Name page, enter these certificate request details:
  2. Common Name (CN) — The fully qualified domain name of the device you want to secure, such as host.example.com.
  3. Department Name (OU) — Enter the OU (Organizational Unit) that the device belongs to, such as IT or Sales.
  4. Company Name (O) — Enter the company name.
  5. City/Location (L) — Enter the city or location where the device is located.
  6. State/Province (ST) — Enter the two-character state or province code where the device is located.
  7. Country (C) — Enter the two-character country code where the device is located.

Screenshot of the Specify Subject Name page for a CSR, at device level

  1. Click Next.
  2. On the Specify Domain page, from the Type drop-down list, select the type of certificate request.
  3. Enter these details:

    • DNS Name — The DNS name of the device you want to secure, such as host.example.com.
    • IP Address — The IP address of the device you want to secure.

    The IP Address text box appears when you create a CSR from the Device Certificates page.

    • Email address — The email address associated with your request.

Screenshot of the Specify Domain page for a CSR

  1. Click Next.
  2. On the Select the Encryption and Key Usage page, select the Algorithm, Key Length, and Key Usage. By default, the certificate uses RSA encryption, 4096-bit key length, and both encryption and signatures for key usage.

Screenshot of the Encryption and Key Usage page for a CSR

  1. Click Next.
    The Finish page opens.

Screenshot of the Finish page for a CSR

  1. Click Download CSR and save the file on your computer.
  2. Send this CSR to a certificate authority (CA) to obtain a signed certificate.
  3. Click Done.
  4. Select the CSR tab to view your CSR in the list. When you receive the signed certificate, the pending CSR is removed from this list.

Next Steps

After you receive the signed certificate from the CA, you can add it to WatchGuard Cloud or a specific device. For more information, go to Add a Certificate.

Request a Let's Encrypt Certificate

The feature described in this section is only available to participants in the WatchGuard Firebox Management Beta program. If a feature described in this section is not available in your version of Fireware, it is a beta-only feature.

To use this feature, your Firebox must run Fireware v2026.4 or higher.

Use the Let's Encrypt service to request a certificate from WatchGuard Cloud as an alternative to the standard CSR workflow. The Let's Encrypt certificate service is available only through Device Configuration > Device Certificates for cloud-managed Fireboxes.

The Let's Encrypt certificate service is not available from Administration > Certificates. The Firebox must communicate directly with Let's Encrypt to validate the domain and obtain the certificate.

To request a certificate with Let's Encrypt:

  1. Select the CSR tab.
  2. Click Create CSR.
  3. From the Encryption Service drop-down list, select Let's Encrypt.
  4. Select the I have read the Let's Encrypt Terms and Conditions check box.

When you select Let's Encrypt, WatchGuard Cloud does not require subject name information such as Company Name, Department Name, City/Location, State/Province, or Country.

  1. Click Next.

Screenshot of the Let's Encrypt option in the Create CSR Wizard

  1. On the Specify Domain page, in the DNS Name text box, enter the fully qualified domain name (FQDN) of the device you want to secure, such as host.example.com.

Screenshot of the Specify Domain page in the Let's Encrypt workflow

  1. Click Next.
  2. On the Select the Encryption page, select the Algorithm and Key Length. By default, the certificate uses RSA encryption, 4096-bit key length.

Screenshot of the Select the Encryption page in the Let's Encrypt workflow

  1. Click Next.
    The Finish page opens.
  2. On the Finish page, click Done.

Screenshot of the Finish page in the CSR Let's Encrypt workflow

WatchGuard Cloud sends the certificate request to the Firebox. The Firebox communicates directly with Let's Encrypt to obtain the certificate. After Let's Encrypt issues the certificate, it appears in the certificate list and includes an (ACME) tag. The Firebox automatically renews the certificate before it expires, which eliminates the need to create and submit a new certificate request for each renewal.

Related Topics

Manage Certificates in WatchGuard Cloud

Configure the Web Server Certificate for Firebox Authentication in WatchGuard Cloud

Import and Install a Third-Party Web Server Certificate