If you have searched for "Shopify CSR", you probably want HTTPS on a Shopify store that uses your own domain. The short answer is that Shopify doesn't take a CSR: it issues and renews the SSL certificate for every connected domain itself, free of charge. This guide explains why, what to do when the padlock is missing, and the rare cases where you really do need a CSR somewhere else.
You can't generate a CSR in Shopify, and you don't need one. When your domain is connected to Shopify with the right DNS records, Shopify issues a free SSL certificate automatically and renews it for you. If the store shows "SSL pending" or "not secure", fix the domain's A and CNAME records instead. You need a CSR only for a website or server outside Shopify that needs a certificate bought from a certificate authority.
1. Why Shopify has no CSR option
A Certificate Signing Request (CSR) is the text you send to a certificate authority when you buy a certificate for a server you run. It is generated together with a private key, and the key must stay on that server.
On Shopify, you don't run the server. Shopify hosts the store and manages its certificates. It obtains a certificate for each domain you connect and renews it automatically. There is no screen in the Shopify admin to generate a CSR, and Shopify's standard plans don't let you upload a certificate you bought elsewhere.
That means:
- Don't buy an SSL certificate for a Shopify store. You can't install it.
- A missing padlock is almost always a DNS problem, not a certificate problem.
- A CSR made on your computer with OpenSSL is of no use to Shopify.
2. How Shopify SSL works for your own domain
- Connect the domain in Shopify.In the Shopify admin, open Settings › Domains and choose to connect an existing domain. Shopify shows the DNS records it expects.
- Point the domain at Shopify.Add those records wherever your domain's DNS is managed (see section 3). Shopify's usual records are an A record for the root domain and a CNAME for
wwwpointing at your store; always copy the values from Shopify's own screen or help page, because they can change. - Verify.Back in Settings › Domains, use Shopify's verify option.
- Wait for the certificate.Once the records resolve, Shopify requests the certificate. It is often ready within minutes to hours; Shopify's help pages allow up to about 48 hours.
- Check the padlock.Open
https://yourdomain.comandhttps://www.yourdomain.com. Both should load with a padlock and no warning.
Pointing your website at Shopify changes only the web records (the root A record and the www CNAME). Leave your MX, SPF and DKIM records alone and your email continues exactly as before.
3. Where to add the DNS records for a Domain India domain
Add the records in the place your domain's DNS is actually answered from. The DNS settings guide explains how to tell.
| Your domain's nameservers point to | Where to add Shopify's records |
|---|---|
| Your Domain India hosting account | Your control panel's DNS editor, for example Zone Editor in cPanel |
| Cloudflare or another DNS provider | That provider's DNS dashboard |
| Shopify (you moved the nameservers to Shopify) | Shopify manages them; you add other records in Shopify |
In the DNS editor, edit the existing root A record and www record rather than adding second copies. Two A records for the same name send half your visitors to the old site and can stop the certificate from being issued. See how to make DNS changes in cPanel for the Zone Editor steps, and how to change your nameservers if you are unsure where DNS lives.
4. Fixing "SSL pending" or a "not secure" warning
| Symptom | Likely cause | Fix |
|---|---|---|
| SSL pending for more than a day | A or CNAME record wrong or missing | Match the records exactly to Shopify's current values |
| Works on www but not the root, or the reverse | Only one of the two records points to Shopify | Point both the root and www at Shopify |
| Certificate error on some visits | A second A record or an AAAA (IPv6) record still points at old hosting | Remove the old records for that name |
| Cloudflare in front of the store | Proxy settings can interfere with verification | Follow Shopify's help for Cloudflare; setting the records to DNS only is the simplest test |
| Certificate never issues | A CAA record that doesn't allow Shopify's certificate authority | Remove the CAA record or add one for the authority Shopify uses |
| Padlock present but "not fully secure" | A theme or app loads an image or script over http:// | Change the link to https:// |
Check what the world sees with a public DNS lookup, for example:
dig +short A yourdomain.com
dig +short CNAME www.yourdomain.com
dig +short AAAA yourdomain.com
dig +short CAA yourdomain.comThe answers must match what Shopify asks for, and the AAAA and CAA lookups should return nothing, or values that don't conflict. After a change, allow time for the old records to expire from caches.
5. When you really do need a CSR
You need a CSR only for a server you control, and only when you buy a certificate from a certificate authority, for example an organisation-validated certificate a bank or tender asks for. Typical cases next to a Shopify store:
- a separate website, blog or app on your own hosting or VPS;
- a subdomain such as
api.yourdomain.comthat you run yourself.
Generate the CSR on the server that will use the certificate. On our hosting, cPanel has a CSR form, and most sites there need no CSR at all because free certificates are issued automatically; see how to generate a CSR on Domain India hosting.
On a Linux server or VPS, OpenSSL creates the key and the CSR in one command. Modern certificates are checked against the Subject Alternative Name (SAN), so include every hostname there:
openssl req -new -newkey rsa:2048 -nodes \
-keyout yourdomain.key -out yourdomain.csr \
-subj "/C=IN/ST=Maharashtra/L=Pune/O=Your Company Pvt Ltd/CN=yourdomain.com" \
-addext "subjectAltName=DNS:yourdomain.com,DNS:www.yourdomain.com"
# check it before you send it
openssl req -in yourdomain.csr -noout -textSend the .csr file to the certificate authority. Keep yourdomain.key on the server with tight permissions (chmod 600) and never email it or paste it into a chat. Windows doesn't include OpenSSL by default; use the copy that comes with Git for Windows, or generate the CSR on the server itself.
Even if a certificate authority issues a certificate from your CSR, Shopify won't accept it for your store. Keep paid certificates for servers you run yourself.
6. Domain India, Shopify and SSL
Domain India doesn't sell SSL certificates as a separate product. Every Domain India hosting plan includes free SSL: on cPanel, AutoSSL issues and renews Let's Encrypt certificates automatically, and DirectAdmin and Plesk use Let's Encrypt too. For a Shopify store, Shopify's own free certificate is all you need.
Where we help: registering the domain your store uses, managing its DNS, and hosting the parts that live outside Shopify, such as a blog, a landing page or business email. You can register a domain at domain registration and compare hosting on cPanel hosting.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
The card price is a Domain India list price on 19 September 2026, excluding 18% GST.
Frequently asked questions
How do I generate a CSR in Shopify?
You can't, and you don't need to. Shopify issues and renews a free SSL certificate for every domain connected to your store. There is no CSR option in the Shopify admin.
Can I install my own SSL certificate on a Shopify store?
Not on Shopify's standard plans. Shopify manages the certificate for connected domains itself, so a certificate bought elsewhere can't be installed there. Don't buy one for a Shopify store.
Why does my Shopify domain say SSL pending?
Usually because the DNS records don't match what Shopify expects. Check the root A record and the www CNAME against Shopify's current values, remove any leftover A or AAAA records that point at old hosting, and allow time for DNS to update.
Will connecting my domain to Shopify break my email?
No, as long as you change only the web records Shopify asks for. Your MX, SPF and DKIM records stay as they are, so email keeps working.
Where do I change DNS records for a domain registered with Domain India?
Wherever your domain's nameservers point. If they point to your Domain India hosting, use your control panel's DNS editor, such as Zone Editor in cPanel. If they point to Cloudflare or another provider, change the records there.
When do I need a CSR at all?
Only when you buy a certificate from a certificate authority for a server you run yourself, such as your own website or VPS. Generate the CSR on that server and keep its private key there.
Does Domain India sell SSL certificates?
Not as a separate product. Every Domain India hosting plan includes free SSL certificates that are issued and renewed automatically. If you need a certificate from a particular authority, buy it there and install it on your hosting.
Ready to connect your store? Check your records with the DNS settings guide, or open a support ticket with your domain name if the records won't save or the domain won't verify.
Register your store's domain with Domain India then point it at Shopify with two DNS records.
Search for a domain