> ## Documentation Index
> Fetch the complete documentation index at: https://help.enrolweb.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Reissuing SSL

> Reissue your EnrolWeb SSL certificate when you lose the private key, change domains, or need to update the certificate after a security incident.

Reissuing generates a new SSL certificate under your existing order, without paying again. Use it when your private key is lost or compromised, when you need to add or change a domain name, or after a security incident.

## When to reissue

<CardGroup cols={2}>
  <Card title="Lost private key" icon="key">
    You no longer have access to the original private key.
  </Card>

  <Card title="Compromised key" icon="triangle-exclamation">
    The private key was exposed or leaked.
  </Card>

  <Card title="Domain change" icon="globe">
    You need to add, remove, or update covered domains.
  </Card>

  <Card title="Server migration" icon="server">
    You're moving to a new server and want a fresh certificate.
  </Card>
</CardGroup>

## Reissue your certificate

<Steps>
  <Step title="Generate a new CSR">
    Create a new Certificate Signing Request on the server where the certificate will live. See \[Activating Your SSL]\(/SSL & Website Security/contact-2) for detailed CSR steps.
  </Step>

  <Step title="Open your certificate order">
    In your EnrolWeb dashboard, go to **SSL Certificates** and open the certificate you want to reissue.
  </Step>

  <Step title="Click Reissue">
    Choose **Reissue Certificate** from the actions menu.
  </Step>

  <Step title="Submit the new CSR">
    Paste your new CSR and update any domains on the certificate if allowed.
  </Step>

  <Step title="Revalidate">
    Complete domain validation (email, DNS, or HTTP) again.
  </Step>

  <Step title="Install the new certificate">
    Once issued, replace the old certificate on your server. See \[Installing SSL]\(/SSL & Website Security/contact-2-2).
  </Step>
</Steps>

## Things to know

<Warning>
  Reissuing revokes the old certificate. Any device still using the old certificate stops trusting your server once the old one is revoked.
</Warning>

* Reissue is free during the certificate's validity period
* Reissue doesn't extend your certificate expiration date
* For OV and EV certificates, organization validation carries over if company details haven't changed
* Adding or removing SAN entries on a multi-domain certificate is allowed on reissue

## After a compromise

If you believe your private key was exposed:

<Steps>
  <Step title="Reissue immediately">
    Start the reissue process right away to invalidate the old key.
  </Step>

  <Step title="Rotate related secrets">
    Change any passwords, API keys, or credentials stored on the same server.
  </Step>

  <Step title="Review server security">
    Audit user accounts, SSH keys, and firewall rules.
  </Step>

  <Step title="Notify affected parties">
    If required by regulation, notify users or authorities.
  </Step>
</Steps>

<Tip>
  Store your private key in a secure secrets manager rather than plain files on the server whenever possible.
</Tip>

Need help reissuing? Contact [support@enrolweb.com](mailto:support@enrolweb.com).
