2 ms·
Process - Know where your key is - Know how to generate a new CSR from that key It's adviced to use a NEW private key, in case there was a private key comp
by bwblabs 12y ago
Process
- Know where your key is
- Know how to generate a new CSR from that key
It's adviced to use a NEW private key, in case there was a private key compromise you didn't know about.
Also see https://www.ssllabs.com/downloads/SSL_TLS_Deployment_Best_Practices_1.3.pdf https://www.ssllabs.com/downloads/SSL_TLS_Deployment_Best_Pr... (point 1.2).
BTW there is NO reason to regenerate the CSR if you reuse the private key.
- zrail 12y agoAh, that makes total sense. I'll update the post and the script. Thanks! Edit: updated
- mortenlarsen 12y agoYou should not reuse private keys, you are wasting a opportunity to replace it if it has been compromised without your knowledge.