3 ms·
This is completely the wrong approach. Your private key might have been compromised and you're generating another certificate for the same compromised private k
by grittygrease 13y ago
This is completely the wrong approach. Your private key might have been compromised and you're generating another certificate for the same compromised private key? What is that supposed to do?
- schrodinger 13y agoI think you misread... the poster said they used a new private key with the same CSR.
- grittygrease 13y agoThe CSR contains the public key for a unique private key. How do you have a new private key with an old CSR?
- dpiddy 13y agoAs discussed on twitter (https://twitter.com/grittygrease/status/453606054698692608 https://twitter.com/grittygrease/status/453606054698692608), I should have said: We generated new CSRs, with new private keys, but with the same dates and details as the originals. This let us get fresh certs without going through a full renewal. Thanks for the prod.
- grittygrease 13y agoThanks for the update. Happy revocation day!