When to reissue
Lost private key
You no longer have access to the original private key.
Compromised key
The private key was exposed or leaked.
Domain change
You need to add, remove, or update covered domains.
Server migration
You’re moving to a new server and want a fresh certificate.
Reissue your certificate
1
Generate a new CSR
Create a new Certificate Signing Request on the server where the certificate will live. See [Activating Your SSL](/SSL & Website Security/contact-2) for detailed CSR steps.
2
Open your certificate order
In your EnrolWeb dashboard, go to SSL Certificates and open the certificate you want to reissue.
3
Click Reissue
Choose Reissue Certificate from the actions menu.
4
Submit the new CSR
Paste your new CSR and update any domains on the certificate if allowed.
5
Revalidate
Complete domain validation (email, DNS, or HTTP) again.
6
Install the new certificate
Once issued, replace the old certificate on your server. See [Installing SSL](/SSL & Website Security/contact-2-2).
Things to know
- Reissue is free during the certificate’s validity period
- Reissue doesn’t extend your certificate expiration date
- For OV and EV certificates, organization validation carries over if company details haven’t changed
- Adding or removing SAN entries on a multi-domain certificate is allowed on reissue
After a compromise
If you believe your private key was exposed:1
Reissue immediately
Start the reissue process right away to invalidate the old key.
2
Rotate related secrets
Change any passwords, API keys, or credentials stored on the same server.
3
Review server security
Audit user accounts, SSH keys, and firewall rules.
4
Notify affected parties
If required by regulation, notify users or authorities.
.png?fit=max&auto=format&n=dGkoxjFuwLusXp7Z&q=85&s=32c3cb11b5a290cd869640fca5093944)