What you need to know about reissuing an SSL Certificate

Over the course of your SSL certificate's lifespan, it may be necessary for you to reissue it at some point. This can happen for a number of reasons:

  • Your private key has been compromised
  • You are adding/removing SAN's
  • Industry updates
  • Changing hashing algorithms
  • Moving servers

The good news is that, outside of time, it probably won't cost you anything—most SSL certificates come with unlimited free reissuances for their entire lifespan.

What do you need before you start?

Before you re-issue your SSL Certificate, make sure that you have the appropriate CSR. For that, you may use either one of the following:

  1. Original CSR – this is the old CSR you used to issue the certificate previously (note: only do this if you still have access to the Private Key that was generated with that CSR AND there are no issues that require you to create a brand new key, such as a private key compromise). 
  2. New CSR – create a new CSR using either an online tool or directly from your webserver (recommended – you can find instructions on how to generate a new CSR on your server here).

Note: If you generate a new CSR, make sure you save your Private key in a safe place. You will need it to install the re-validated certificate later.

Steps to Reissue

1. Log in to your account on CheapSSLSecurity.com

Login to your CheapSSLSecurity account to access your orders. If you're already logged in but not on your order dashboard, click My Dashboard on the top right of the homepage.

2. Find the order that you want to re-issue

Use your Asset menu to locate the certificate you need to re-issue. If you have many assets, you can search for the domain name to narrow it down. When you find the domain name, click on it to view all certificates for that domain.

If you ordered the certificate recently, you can also use the Recent Orders menu to find it. 

OR, if the certificate is expiring soon, click on the Re-Issue/Renew action buttons along the top of the dashboard.

3. Find Certificate on Asset page

On the Assets page, click the Manage button in the SSL Certificates window to jump to your list of certificates using this domain.

Then, on the Certificates list, click the order you need to re-issue. 

4. Manage Order - Select “Re-Issue Certificate”

On the Manage Order page, click the button to Re-Issue the SSL Certificate.


5. Complete enrollment - paste your CSR

Fill out the enrollment form with all requested details. You will need a certificate signing request (CSR). 

If you're re-issuing because of an issue with your private key, please create a new CSR on your server. 

If there's no issue with your original CSR or key, you may be able to use the previous CSR.

6. Select domain validation method

Select your preferred method to validate the domain name(s) on the certificate. You may be required to complete this step after submitting the re-issue request before the new certificate can be activated. 

7. Review your details and submit

Double-check that your enrollment details are correct. You may not be able to change them after submitting the order.

8. Complete any necessary validation steps

You may need to undergo the validation process again if any certificate details have changed, or if it has been a while since you previously completed validation. Check your dashboard for domain validation instructions, plus updates on any other validation steps the Certificate Authority needs to complete. 

After you complete the validation process and have received the reissued SSL Certificate, you can proceed to installing the new certificate. You can find instructions on installing SSL on different servers on our Installation page.