A file containing a public key and team identity, signed with the matching private key. You upload it to Apple to be issued a certificate. The private key never leaves your machine in the process.
A Certificate Signing Request (CSR) is the file you give Apple to be issued a code signing certificate. It is a PKCS#10 structure containing a freshly-generated public key plus the team's identity, all signed by the matching private key as proof that you hold it. Apple's portal accepts the CSR, verifies the signature, and issues a certificate that wraps the same public key.
Why Apple wants a CSR instead of just a public key
It proves you actually have the private key (you signed the request with it).
It commits you to a specific public key, so the issued certificate binds to a key only you control.
It is a standard PKI format. Apple did not have to invent anything.
Generating one
bash
# Keychain Access:
# Keychain Access > Certificate Assistant > Request a Certificate from a CA
# - email: anything, Apple does not validate it
# - common name: a label you will recognize later
# - 'Saved to disk' (not 'Emailed to the CA')
# openssl equivalent
openssl req -new -newkey rsa:2048 -nodes \
-keyout HexSignDist.key \
-out HexSignDist.csr
Reuse vs regenerate
When a certificate is about to expire, you can either generate a brand new CSR and a new private key, or reuse the same CSR (and therefore the same private key) and issue a fresh certificate against it. Reusing means every artifact that already trusts the public key, like a long-lived provisioning profile or an embedded certificate hash, keeps working. Most teams reuse for App Store distribution and rotate keys only when they are forced to (compromise, lost key, policy).
FAQ
Common questions about CSR (Certificate Signing Request)
Open Keychain Access, then Certificate Assistant, then Request a Certificate from a Certificate Authority. Enter any email, a common name you will recognize later, choose Saved to disk, and save the .certSigningRequest file. The matching private key lands in your keychain, which is the part to protect.
Yes. A CSR is standard PKI, so openssl generates one on any OS: openssl req -new -newkey rsa:2048 -nodes -keyout dist.key -out dist.csr. Apple's portal accepts it fine. Services like HexSign generate the CSR server-side and keep the private key encrypted, which removes the single-Mac dependency entirely.
No. It carries the public key, your identity details, and a signature made with the private key as proof of possession. The private key itself never leaves the machine (or vault) that generated it, which is why sending a CSR to Apple is safe.
Yes. Apple accepts the same CSR again, and the new certificate binds to the same public key. Teams do this on rotation so existing provisioning profiles and pinned keys keep working. Generate a fresh CSR instead when you have any reason to distrust the old private key.
HexSign tracks every Apple certificate and provisioning profile and alerts you ahead of expiry. The Free plan covers tracking and alerts. Paid plans renew them for you.