---
title: Using a self-signed SSL cert on MacOS
url: https://calvin.my/posts/using-a-self-signed-ssl-cert-on-macos
published: 2024-08-15
updated: 2026-09-17
category: Etc
tags:
- SSL
- OpenSSL
- MacOS
- Security
summary: The post explains how to create and trust a self-signed SSL certificate for local HTTPS development on macOS. It emphasizes configuring certificate details, including subject alternative names and the digital signature key usage required by modern browsers. After generating the certificate and optionally converting it to other formats for compatibility, users import it through Keychain Access and set its trust level to allow browsers to recognize the local HTTPS site.
---

# Using a self-signed SSL cert on MacOS

## Creating a cert

1. Construct a requirement config and save the file as "req.conf".

   ```conf
   [req]
   distinguished_name = req_distinguished_name
   x509_extensions = v3_req
   prompt = no
   [req_distinguished_name]
   C = MY
   ST = Kuala Lumpur
   L = Kuala Lumpur
   O = Company Name
   CN = localhost
   [v3_req]
   keyUsage = digitalSignature, keyEncipherment, dataEncipherment
   extendedKeyUsage = serverAuth
   subjectAltName = @alt_names
   [alt_names]
   DNS.1 = localhost.abc
   DNS.2 = localhost
   ```

2. It is important to include "digitalSignature" in the keyUsage field, otherwise modern browsers would block the cert.

3. Run the following OpenSSL command to generate the certificate. Replace the "days" value as needed.

   ```bash
   openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout key.pem -out certificate.pem -config req.conf -extensions 'v3_req'
   ```

4. Run the following OpenSSL command to get the P12 format.

   ```bash
   openssl pkcs12 -inkey key.pem -in certificate.pem -export -out certificate.p12
   ```

   If this certificate is also used on older system (E.g. Windows 7), please include the -legacy option.

   ```bash
   openssl pkcs12 -legacy -inkey key.pem -in certificate.pem -export -out certificate.p12
   ```

5. Or if you need a JKS format.

   ```bash
   keytool -importkeystore -srckeystore certificate.p12 -srcstoretype pkcs12 -destkeystore certificate.jks -deststoretype jks
   ```
* * *
## Install Cert on MacOS

1. Go to the "Keychain Access" App on your device.

2. Select "Files", then "Import Items".

3. Select the cert file that you created earlier.

4. Double clicks on the imported cert and expand the trust section

   ![](https://camy-pub.s3.ap-southeast-1.amazonaws.com/36e80ae7-1c2f-4caa-acae-a885ef83df34.png)

5. Set it to "Always Trust".

6. Now you can try to access the HTTPS URL from your browser, and it should be trusted.
