We offer unlimited free reissues for any SSL certificate purchased through our store. You may need to reissue your certificate if you lost your private key, migrated to a new server, or need to make key configuration changes.
Note: Certificates can only be reissued if their status is "Active" or "Issued." You cannot reissue a certificate while it is currently processing or if another reissue request is pending.
Common Reasons to Reissue Your SSL
-
Lost Private Key (RSA Key)
-
Moving your website to a new server
-
Encountering a "modulus mismatch" error during installation
-
Changing your Common Name (Domain)
-
Adding or updating SAN items for Multi-Domain certificates
-
Certificate Authority (CA) compliance updates or security requirements
How to Reissue Your SSL Certificate
-
Step 1: Go to Your SSL Product
- Locate your SSL product in the client area.
- Click on the Configure Now button at the bottom of the window.
Step 2: Select Order Type
- If you’re ordering a new SSL certificate or haven’t purchased one from us before, select New Order
- If you’re renewing an existing certificate, select Renewal
Step 3: Generate CSR (Certificate Signing Request)
Method 1 (Recommended) – Server Side
- Generate the CSR from your server.
- Copy and paste the CSR into the required field in your client area.
Method 2 – From Client Area
- Click Generate CSR to create the CSR and keys.
- Fill in the required form to proceed.
- After submission, the CSR details will appear in the CSR section.
Step 4: Fill Administrative Contact Form
- Scroll down and fill in the administrative contact form with the correct details.
- Click Continue to proceed.
Step 5: Domain Validation
- On the next page, select a domain validation method from the available options.
- Complete the validation process and click Continue.
Domain Validation Methods :
1. Email Validation
- Select Email Validation during the SSL configuration.
- Choose one of the default approval email addresses. ( admin@<yourdomain>, administrator@<yourdomain>, hostmaster@<yourdomain>, webmaster@<yourdomain> and postmaster@<yourdomain>)
- An approval email will be sent to the selected address.
- Open the email and click the approval link to validate.
(Ensure the selected email address exists and is accessible before choosing this method.)
2. DNS (CNAME) Record Validation
Steps:
- Select DNS Validation during configuration.
- The CA will provide a CNAME record (name and value).
- Add the provided CNAME record to your domain’s DNS zone.
- Wait for DNS propagation ( It takes from 10 minutes and up to 24 hours to validate domain; it depends on your DNS server TTL).
- The CA automatically checks and validates your domain.
3. HTTP File Upload (File-Based Validation)
Steps:
- Select HTTP Validation.
- The CA provides a validation file and a specific path to upload it.
(e.g., http://<yourdomain>/.well-known/pki-validation) - Upload the file to your web server in the given path.
- The CA will access the URL to verify the file.
(This method requires control over the website’s root directory.)
Final Step: SSL Certificate Issuance
- Once the domain validation is successfully completed, the SSL certificate will be sent to your email.
- Alternatively, you can download it directly from your client area.
Key Reissue Rules to Keep in Mind
-
Using the Original CSR: If you reissue using your original CSR code, the certificate reissues automatically without requiring re-validation.
-
Changing the Common Name (Domain): You can change your primary domain by submitting a new CSR with the new domain name. Warning: Your previous SSL certificate will be revoked immediately.
-
Updating SAN Items: You can modify SAN items for Multi-Domain SSLs during the reissue process. Input SANs in the dedicated form fields (SANs embedded inside the CSR code itself are ignored). You only need to validate newly added SAN items if using the original CSR.