Reissue an SSL/TLS certificate
All DigiCert certificates come with unlimited free reissues. The list below includes some reasons for reissuing a certificate:
Lost the private key and want to re-key the certificate.
Change the common name on the certificate (for example, you want to remove example.com and add yourdomain).
Add, remove, or change some subject alternative names (SANs) in the certificate.
Before you begin
The certificate reissue process allows you to modify an issued certificate. Some modifications enable you to build upon the original certificate, resulting in two or more versions of that certificate. For example, when reissuing a certificate, you can add domains to the original certificate. Adding domains to a certificate doesn’t revoke the original certificate.
Other modifications allow you to create a new version of the certificate and require DigiCert to revoke the original certificate and any existing certificate reissues and duplicates. For example, removing SANs or changing SANs on a multi-domain certificate creates a new version of the certificate, revoking the original certificate and any previous reissues and duplicate copies.
Reissue certificate
Step 1: Generate CSR
To reissue an SSL/TLS certificate, you must generate a new CSR. For more information about creating a CSR, see Create a CSR (Certificate Signing Request).
Best practices are to generate a new certificate signing request (CSR) when reissuing your SSL/TLS certificate. Generating a new CSR creates a new, unique keypair (public/private) for the reissued certificate.
Step 2: Sign in to CertCentral and request a TLS/SSL certificate reissue
In CertCentral, fill out the certificate reissue request form and modify the certificate details as needed.
In CertCentral, go to the certificate’s Order # details page.
In the left menu, go to Certificates > Orders.
On the Orders page, select the Order # of the certificate you need to reissue.
For CertCentral Subscription accounts:
In the left menu, go to My Digital Trust Products > Certificates.
On the Certificates page, select the Order # of the certificate you need to reissue.
On the certificate's Order # details page, in the Certificate actions menu, select Reissue certificate.
Depending on your changes, the original certificate and previous versions (reissues and duplicates) may need to be revoked. However, before you submit the reissue request, we warn you if a change requires revocation.
How does the revocation process work?
If a certificate reissue requires revocations, after reissuing the certificate, DigiCert revokes the original certificate and any existing duplicates and reissues within 72 hours.
We also do the following:
Send the requestor a revocation warning email with the subject line: Reissue request will revoke previously issued certificate for order ###### within 72 hours.
Change the Certificate status to Revocation pending with the revocation date and time on the Certificate history page.


Step 3: Complete domain control validation (DCV)
If you have unvalidated domains on the certificate reissue request (common name or SANs), you must demonstrate control over those domains before DigiCert can reissue the certificate. See Demonstrate control over domains on a pending certificate order.
Step 4: Complete organization validation
If the organization validation has expired, DigiCert must complete the organization validation before we can reissue the certificate. See SSL/TLS certificate organization validation process.
Step 5: DigiCert reissues the SSL/TLS certificate
Once approved, we reissue and email the new certificate to the certificate contact. You can also download the reissued certificate from your account. See Download a TLS/SSL certificate from your CertCentral account.
Warning
Pending certificate revocations
If certificate revocations are required, replace soon-to-be revoked certificates within 72 hours from when your certificate is reissued.
Step 6: Install your reissued SSL/TLS certificate
Install and configure the new certificate. For more information about installing your certificate, see our SSL Certificate Installation Instructions & Tutorials page.
Reissue FAQ
Question: Do I need to create a new CSR when I reissue my SSL/TLS certificate?
Answer: Yes. Best practices are to generate a new certificate signing request (CSR) when reissuing your SSL/TLS certificate. Generating a new CSR creates a new, unique key pair (public/private) for the reissued certificate. For more information, see Create a CSR.
If you have a Windows server, you can use the free DigiCert Certificate Utility for Windows , which has an easy CSR generator for Windows servers.