Reissuing Your SSL Certificate Step by Step

An SSL Certificate has two separate expiry dates, and the earlier of the two arrives long before your license ends. When that date approaches, you replace the SSL Certificate yourself through a reissue.

A reissue costs nothing, is included with every license, and normally takes a few minutes. This page walks through the entire procedure for someone who has never done it before.

The Reason an SSL Certificate Expires Before the License

Your license is your entitlement to hold a valid SSL Certificate for the period you paid for and where you subsequently continue to prove control of the secured domain names. The SSL Certificate itself is a separate file that industry regulations now force to be much shorter lived than most license periods.

A one year license therefore covers a period longer than any single SSL Certificate is permitted to last. The license does not shrink, and nothing has been taken away from you. You simply collect a fresh SSL Certificate part way through and prove your right to continue to hold that SSL Certificate. Learn About The Reason Behind Reissues 🔗

Recognizing That a Reissue Is Due

The two dates sit side by side in the tracking system. One panel shows your license dates, and the panel beside it shows the validity dates of the last SSL Certificate issued. The second of those is the one that causes browser warnings.

Watching the validity remaining figure rather than the license remaining figure is the habit worth forming. The validity dates are encoded within the SSL Certificate itself, so the primary method of following these dates is by monitoring the server or hosting control panel where it is installed.

The tracking system also provides calendar files for both dates, which you can add to your own calendar so the reminder arrives without you needing to check. Learn About The Tracking System 🔗

Note : Trustico® does not hold records of where your SSL Certificates are installed and cannot detect that a website is serving an expiring SSL Certificate. Watching the validity dates remains your own responsibility and is a normal business function when operating a secure website.

Reissuing a few weeks ahead of the validity end date is more comfortable than reissuing on the day, because it leaves room for validation to be completed without pressure.

What to Have Ready Before You Start

You need your Certificate Authority (CA) Reference. This is not the same as your Trustico® order number, and the order number will not grant access, because a single order is capable of securing many domain names across several separate SSL Certificates.

The reference appears in the e-mail sent when your order reached the Certificate Authority (CA). It is also held within the ordering and billing systems where the order was placed, and it is shown inside the tracking system once you are signed in. Learn About Telling the Two Numbers Apart 🔗

You also need to decide whether you will supply a new Certificate Signing Request (CSR) or reuse the one already held by the Certificate Authority (CA). If you intend to supply a new one, generate it on the server where the SSL Certificate will be installed before you begin. Learn About Generating a Certificate Signing Request 🔗

Finally, make sure you have access to whichever validation method you plan to use, whether that means a mailbox, your Domain Name System (DNS) records, or the web server for the domain name.

Accessing the Tracking System

Access is granted per license rather than through a general account, so there is no password to remember and nothing to set up in advance.

Note : The tracking system supports traditional SSL Certificates only. Certificate as a Service (CaaS) products are maintained entirely by your own Automated Certificate Management Environment (ACME) client, and Trustico® performs no part of that process.

If you hold a Certificate as a Service (CaaS) product, the procedure described on this page does not apply to you. Issuance, validation and replacement all happen automatically on your own server, without a reissue ever being requested by hand. Learn About Certificate as a Service 🔗

Details Requested on the First Screen

You are asked for your Certificate Authority (CA) Reference, the domain name covered by the SSL Certificate, and the brand of the product you ordered, which is chosen from a list. A human verification check also appears on the same screen.

All three details must match the order. If the reference is rejected, the most common cause is that the order number was entered instead of the Certificate Authority (CA) Reference.

The Additional Security Code

A second screen may then ask for a security code. Whether it appears depends on a number of security factors, so its absence does not mean anything is wrong.

When it does appear, the code can be delivered by text message, by a messaging application, by voice call, or to an e-mail address that is not held with a free e-mail provider. Choose whichever you can reach immediately, because the code is intended for use straight away.

Reading Your Dashboard

Once you are in, the dashboard shows the current state of the license and every action available to you. Three areas matter before you reissue anything.

The Two Sets of Dates

License Information shows the start date, end date, duration and remaining days of your entitlement. SSL Certificate Issuance beside it shows the same four figures for the last valid SSL Certificate issued.

Seeing a large number of license days remaining alongside a much smaller number of validity days remaining is normal, and it is precisely the situation a reissue exists to resolve.

The Validation Progress Indicator

Three stages are shown : the Certificate Signing Request (CSR), Domain Control Validation (DCV), and Certification Authority Authorization (CAA). All three must complete before an SSL Certificate can be issued.

The third stage checks the Domain Name System (DNS) records that state which Certificate Authorities are permitted to issue for your domain name. It usually passes without any action on your part. Learn About Certification Authority Authorization Records 🔗

Choosing the Reissue Action

The available actions are grouped together lower down the dashboard. The one you want replaces your SSL Certificate within the license you already hold, and it will issue for the longest validity currently permitted, or to the end of your license period where that is sooner.

Alongside it you will find the option to download an SSL Certificate that has already been issued, which is where you will return once the reissue completes.

Step 1 : Choosing Your Certificate Signing Request

The reissue offers two routes. You can supply a new Certificate Signing Request (CSR), or you can use the one already on record with the Certificate Authority (CA). Both are valid.

Reusing the record held by the Certificate Authority (CA) is the quicker route, particularly if you go on to choose the same validation method you used originally. Generating a new Certificate Signing Request (CSR) produces a new Private Key, which is better security practice, and is the route to take if the existing key has been exposed or lost.

Important : Where you supply a new Certificate Signing Request (CSR), the primary domain name inside it must match the primary domain name on the original order. A mismatch will prevent the reissue from proceeding.

One detail surprises almost everyone the first time. Any additional names written into a Certificate Signing Request (CSR) are ignored, both at reissue and when ordering.

Coverage comes from your license rather than from the request. Only the primary domain name is read from the Certificate Signing Request (CSR), and every name on the license is then added, with one of them designated as the primary name on the SSL Certificate. There is no need to list anything beyond the primary domain name.

Step 2 : Selecting a Validation Method

Every domain name on the license is listed, each awaiting a method. You may configure one domain name and then apply that same method to all the others, which is the sensible choice in most cases, or click an individual domain name to configure it on its own.

A method must always be selected, even where you have validated the same domain name recently. If your previous completion for that method is still inside its reuse period, the check may then complete without anything further being asked of you. Learn About Validation Reuse Periods 🔗

Choosing the method you used originally is therefore the fastest path, because it is the method most likely to still be within its reuse period.

Approver E-Mail Validation

A confirmation e-mail is sent to one of five pre-approved addresses at your domain name, and the recipient follows the instructions it contains. The address is chosen from a list on screen.

The mailbox must already exist and be able to receive e-mail before validation can complete, so create it first if it does not. This method is expected to be phased out in future, so it is not the one to build a routine around.

Domain Name System Validation

Two Domain Name System (DNS) methods are offered, one using a CNAME record and one using a TXT record. Both require you to add a record to the zone for the domain name and leave it in place until the SSL Certificate has been issued.

These methods suit anyone who already administers their own Domain Name System (DNS) records, and they remain available for every product type.

File Based Validation

The two file methods place a file on your web server, reachable over either Hypertext Transfer Protocol (HTTP) or Hypertext Transfer Protocol Secure (HTTPS). They suit anyone with straightforward access to the files and pages being served on the website.

Where either file method is used, regulations require the file to be reachable at every subdomain that is to be secured, and at the root as well where the root is also secured. A file placed in one location alone will not validate the remaining names.

This obligation applies only to the two file methods. Approver e-mail and the two Domain Name System (DNS) methods carry no equivalent requirement, which is why they are usually the easier choice where a license covers many names.

Important : File based validation cannot be used for a Wildcard SSL Certificate. Wildcard entries are limited to approver e-mail, CNAME record, or TXT record validation, and the file options are shown as unavailable.

Once every domain name has a method assigned, the submit button becomes available and reports how many of your domain names have been configured. Learn About The Validation Procedure in Detail 🔗

What Happens After You Submit

Issuance is fast. Once validation and the automated checks that accompany it have completed, the SSL Certificate is usually issued within minutes.

Those automated checks repeat your validation from several independent network locations around the world, and all of them must agree. This is why validation resources must stay in place until the SSL Certificate has actually been issued rather than being removed as soon as the first check passes. Learn About The Automated Corroboration Checks 🔗

Restrictions that limit access to your web server or Domain Name System (DNS) servers by country or by address range are the most frequent reason these checks disagree, so those paths need to be reachable globally while validation is under way.

A misconfigured Domain Name System Security Extensions (DNSSEC) deployment will also prevent issuance, because the records required for the Certification Authority Authorization (CAA) check cannot be resolved and the check is recorded as a failure.

Downloading Your New SSL Certificate

Return to the dashboard and use the refresh action at the top right of the page to update the license and SSL Certificate status.

Then choose the download option. The next screen confirms the issued status, the new validity period, the serial number, and the names covered.

Your SSL Certificate is shown ready to copy, with the Intermediate Certificates shown separately below it. Both are required, because browsers need the full chain in order to establish trust. Learn About Intermediate Certificates 🔗

Several download formats are offered so you can match your server. You can take the SSL Certificate on its own, the chain on its own for servers that expect separate files, the SSL Certificate together with its chain, the same with the root included, or the PKCS#7 format.

An archive containing every format is also available, and the same archive can be sent directly to an e-mail address of your choosing if the person installing it is not you. Learn About Installing Your SSL Certificate 🔗

Your Previous SSL Certificate Stays Active

Reissuing does not switch anything off. Every SSL Certificate issued under your license remains active until its own validity end date unless it is revoked, and the license history records each one.

This means you can reissue early and install at a moment that suits you, with the previous SSL Certificate continuing to serve your website until you replace it. There is no gap and no outage created by the reissue itself.

If Your SSL Certificate Has Already Expired

The procedure is exactly the same. An expired SSL Certificate does not affect your license, and nothing additional is required of you.

As soon as the reissue completes, the new SSL Certificate is available to download and install. The browser warnings stop once it is installed and the web server has been restarted.

When Something Does Not Work

A rejected reference on the first screen is almost always the order number being used in place of the Certificate Authority (CA) Reference. Checking which number you have resolves most access problems immediately.

A reference that has never worked may mean the order has not yet reached the Certificate Authority (CA), which happens while an order is still being processed. Waiting for the e-mail that carries the reference is the correct response.

Validation that starts but never completes usually points at your own infrastructure rather than at the Certificate Authority (CA). Records removed too early, filtering by country or address range, and web servers that reject requests without a recognized browser identifier are the common causes.

Where none of these apply, the Trustico® team can look at the license with you. Contact The Trustico® Support Team 🔗

Avoiding This Every Few Months

Reissuing by hand is manageable while validation can be reused for a long period. That period is scheduled to shorten considerably over the next few years, and at its shortest a manual reissue cycle becomes impractical for anyone managing more than a handful of names.

Certificate as a Service (CaaS) removes the work entirely. Your server requests and validates each new SSL Certificate automatically, so no reissue is ever performed by hand and no validation window needs watching.

That process runs solely on your own side. Your Automated Certificate Management Environment (ACME) client handles each request, and no part of the cycle is performed by Trustico® or tracked through the tracking system.

Certificate as a Service About Reissues

Whichever route you take, the entitlement is the same. Your license covers a valid SSL Certificate for its full period, and reissuing is simply how that coverage is collected. Learn About Managing Shorter Validity Periods 🔗

Most Popular Questions

Frequently asked questions covering the reissue procedure from start to finish, including access to the tracking system, the Certificate Signing Request choice, validation method selection, download formats, and what happens to the previous SSL Certificate.

Purpose of a Reissue Within a License Period

Industry regulations limit how long an individual SSL Certificate may remain valid, and that limit is shorter than most license periods. Reissuing collects a fresh SSL Certificate within the license you already hold, at no additional cost.

Products the Tracking System Supports

The tracking system supports traditional SSL Certificates only. Certificate as a Service (CaaS) products are maintained entirely by the customer's own Automated Certificate Management Environment (ACME) client.

Reissuing a Certificate as a Service Product

No manual reissue is performed for a Certificate as a Service (CaaS) product. Issuance, validation and replacement all happen automatically on the customer's own server, and Trustico® performs no part of that process.

Details Required to Access the Tracking System

The first screen asks for the Certificate Authority (CA) Reference, the domain name covered by the SSL Certificate, and the brand of the product ordered. A human verification check also appears on the same screen.

The Additional Security Code

A security code may be requested on a second screen, delivered by text message, messaging application, voice call, or to an e-mail address not held with a free provider. Whether it appears depends on a number of security factors.

Difference Between the Reference and the Order Number

The Certificate Authority (CA) Reference grants access to the tracking system and the Trustico® order number does not, because a single order is capable of securing many domain names across several separate SSL Certificates. A rejected reference is most often the order number being entered by mistake.

Monitoring the Validity Dates

The validity dates are encoded within the SSL Certificate itself, so the primary method of following them is monitoring the server or hosting control panel where it is installed. Trustico® does not hold records of where SSL Certificates are installed.

Choosing Between a New and an Existing Certificate Signing Request

Both routes are valid. Reusing the request held by the Certificate Authority (CA) is quicker, while generating a new one produces a new Private Key and is the better security practice.

Domain Names Inside a Certificate Signing Request

Only the primary domain name is read from a Certificate Signing Request (CSR). Any additional names written into it are ignored, because coverage comes from the license rather than from the request.

Matching the Primary Domain Name at Reissue

Where a new Certificate Signing Request (CSR) is supplied, the primary domain name inside it must match the primary domain name on the original order. A mismatch prevents the reissue from proceeding.

Selecting a Validation Method for Each Domain Name

A method must always be selected for every domain name on the license. One domain name can be configured and that method applied to all others, or each can be configured individually.

Effect of the Validation Reuse Period

Where a previous completion for the chosen method is still inside its reuse period, the check may complete without anything further being asked. Choosing the method used originally is therefore the fastest path.

Placement Requirements for File Based Validation

Regulations require the file to be reachable at every subdomain that is to be secured, and at the root as well where the root is also secured. This obligation applies only to the two file methods, as approver e-mail and the Domain Name System (DNS) methods carry no equivalent requirement.

Validation Methods Available for Wildcard SSL Certificates

Wildcard entries are limited to approver e-mail, CNAME record, or TXT record validation. Both file based methods are unavailable and are shown as such on screen.

Time Taken for a Reissued SSL Certificate to Be Issued

Once validation and the automated checks that accompany it have completed, the SSL Certificate is usually issued within minutes. Validation resources should stay in place until issuance has finished.

Effect of Domain Name System Security Extensions on Issuance

A misconfigured Domain Name System Security Extensions (DNSSEC) deployment will prevent issuance. The records required for the Certification Authority Authorization (CAA) check cannot be resolved and the check is recorded as a failure.

Download Formats Offered for a Reissued SSL Certificate

The SSL Certificate can be taken on its own, as the chain alone, with its chain, with its chain and root, or in PKCS#7 format. An archive containing every format is also available and can be sent to an e-mail address.

Status of the Previous SSL Certificate After a Reissue

Every SSL Certificate issued under the license remains active until its own validity end date unless it is revoked. Reissuing early therefore creates no gap and no outage.

Reissuing an SSL Certificate That Has Already Expired

The procedure is identical, as an expired SSL Certificate does not affect the license. The new SSL Certificate is available to download as soon as the reissue completes.

Common Causes of Validation Failure at Reissue

Validation resources removed too early, filtering by country or address range, and web servers that reject requests without a recognized browser identifier are the usual causes. Remediation is to your own infrastructure rather than at the Certificate Authority (CA).

Ask Trustico® Assistant

For Instant Answers - Start Here When You Have a Question or Need Help

Formatting Domain Name System (DNS) Records and the Trailing Dot

Formatting Domain Name System (DNS) Records and...

Why some DNS records need a trailing dot and others do not, and how to enter SSL Certificate validation records correctly in zone files and hosting panels.

Formatting Domain Name System (DNS) Records and...

Why some DNS records need a trailing dot and others do not, and how to enter SSL Certificate validation records correctly in zone files and hosting panels.

Merkle Tree Certificates Explained

Merkle Tree Certificates Explained

The move toward post-quantum cryptography solves one problem and creates another. It protects encrypted traffic against future quantum computers, but the new signature algorithms are far larger than the ones...

Merkle Tree Certificates Explained

The move toward post-quantum cryptography solves one problem and creates another. It protects encrypted traffic against future quantum computers, but the new signature algorithms are far larger than the ones...

SSL Certificates and Front-of-Site Services Like Cloudflare

SSL Certificates and Front-of-Site Services Lik...

Learn how front-of-site services like Cloudflare affect which SSL Certificate visitors see and how to apply your purchased SSL Certificate to them.

SSL Certificates and Front-of-Site Services Lik...

Learn how front-of-site services like Cloudflare affect which SSL Certificate visitors see and how to apply your purchased SSL Certificate to them.

Understanding X9 Certificates and the Public Trust Model

Understanding X9 Certificates and the Public Tr...

Learn what X9 Certificates are, how X9 PKI differs from public browser trust, and why they are not a substitute for a publicly trusted SSL Certificate.

Understanding X9 Certificates and the Public Tr...

Learn what X9 Certificates are, how X9 PKI differs from public browser trust, and why they are not a substitute for a publicly trusted SSL Certificate.

Why Your SSL Certificate Type and Brand Matter by Industry

Why Your SSL Certificate Type and Brand Matter ...

Why the type and brand of SSL Certificate matter across regulated industries, who examines your validation standing, and what is at stake when they do.

Why Your SSL Certificate Type and Brand Matter ...

Why the type and brand of SSL Certificate matter across regulated industries, who examines your validation standing, and what is at stake when they do.

Revocation Status Errors on a Valid SSL Certificate

Revocation Status Errors on a Valid SSL Certifi...

A revocation status error such as RevocationStatusUnknown can appear on a valid SSL Certificate. Learn how to confirm it is not revoked and what to do next.

Revocation Status Errors on a Valid SSL Certifi...

A revocation status error such as RevocationStatusUnknown can appear on a valid SSL Certificate. Learn how to confirm it is not revoked and what to do next.

1 / 6