How to Reissue an SSL Certificate
-
A reissue replaces your certificate files with new ones within the same order — the expiration date does not change. A renewal, on the other hand, is a new order that you can connect to the old one to carry over any remaining validity days; see [link to Renewal article]. Reissues are free and unlimited for any SSL certificate purchased from GoGetSSL, and are only possible while the certificate has an active status.
Most Common Reasons to Reissue
- You lost your private key
- You are moving your website to a new server
- You received a "modulus mismatch" error during installation
- You want to change the common name (domain)
- You need to add or modify SAN items on a Multi-Domain certificate
- The CA requires a reissue due to an industry-wide change or other significant reason
How to Reissue Your SSL Certificate
- Log in to your account at my.gogetssl.com
- Go to SSL Certificates, find your certificate, and click View.
- Click the Reissue button.
- Submit your new CSR in the form.
- Select your DCV validation method.
- Complete the reissue process.
- DV certificates are reissued as soon as domain validation is complete. OV/EV certificates require a short recheck by the CA, typically taking 12 to 24 hours.
- Once you receive the reissued files, install them on your server in place of the old ones.
Changing SAN Items and the Common Name
For Multi-Domain certificates, you can update your SAN items during the reissue process. Note that any SAN entries listed inside the CSR itself are ignored — only the domains submitted in the dedicated SAN fields on the reissue form are used.
Changing the common name (the primary domain) is also possible during reissue — simply submit a new CSR containing the new common name. Keep in mind that doing so will instantly revoke the previous certificate.
Things to Remember
- If you reissue using the same (original) CSR, the certificate is reissued automatically with no revalidation needed.
- If you submit a new common name in the CSR, the previous certificate is revoked instantly.
- If you reissue a Multi-Domain certificate using the original CSR, you only need to validate the newly added SAN items.
Reissuing Code Signing Certificates
Sectigo Code Signing certificates use a Replace option, available only for OV and EV orders placed after May 15, 2023 where the certificate was generated using your own token or HSM (such as a Yubikey or Thales Luna device). Replace is not available for certificates provisioned on a USB token issued by Sectigo, or for new orders provisioned by Sectigo on their own token.
To replace a certificate, log in to secure.trust-provider.com using your original order credentials, click Replace, and submit a new CSR with key attestation from your device.
DigiCert and GoGetSSL Code Signing certificates are reissued directly through your GoGetSSL account — find the order and click Reissue Certificate.