You are not logged in.

#1 2009-09-15 13:53:50

murffatksig
Member
From: Atl
Registered: 2004-05-17
Posts: 358

[solved] Renewing a verisign cert

Sorry, this isnt Arch related, but I'm having a tough time googling the correct answer.  I've got a customer using red hat linux and wanting to renew their verisign ssl cert for a webpage.  I'm following the instructions listed at https://knowledge.verisign.com/support/ … t&id=AR142

My question is, do I need to generate a new key pair if i'm renewing the certificate?

Thanks,

MP

Last edited by murffatksig (2009-09-15 20:17:40)


"Oh, they have the internet on computers now."

Offline

#2 2009-09-15 17:33:09

cactus
Taco Eater
From: t͈̫̹ͨa͖͕͎̱͈ͨ͆ć̥̖̝o̫̫̼s͈̭̱̞͍̃!̰
Registered: 2004-05-25
Posts: 4,622
Website

Re: [solved] Renewing a verisign cert

you don't have to.
generally they either:
a) just re-sign the original cert request they have on hand, (new certificate lifetime)
b) ask for a new csr to sign
c) ask you to generate a new key, and then a new csr to sign

I think which operation they prefer depends on the vendor.

https://knowledge.verisign.com/support/ … 3035718053

For the sake of security though, it certainly wouldn't hurt to generate a new private key and csr, and then have that csr signed. (option c above)

another relevant link: http://serverfault.com/questions/42993/ … ith-apache
apparently verisign does allow option a (see last comment on serverfault page)


"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍

Offline

#3 2009-09-15 20:18:25

murffatksig
Member
From: Atl
Registered: 2004-05-17
Posts: 358

Re: [solved] Renewing a verisign cert

Thanks, I went with option B.


"Oh, they have the internet on computers now."

Offline

Board footer

Powered by FluxBB