You are not logged in.
Pages: 1
Sorry, this isnt Arch related, but I'm having a tough time googling the correct answer. I've got a customer using red hat linux and wanting to renew their verisign ssl cert for a webpage. I'm following the instructions listed at https://knowledge.verisign.com/support/ … t&id=AR142
My question is, do I need to generate a new key pair if i'm renewing the certificate?
Thanks,
MP
Last edited by murffatksig (2009-09-15 20:17:40)
"Oh, they have the internet on computers now."
Offline
you don't have to.
generally they either:
a) just re-sign the original cert request they have on hand, (new certificate lifetime)
b) ask for a new csr to sign
c) ask you to generate a new key, and then a new csr to sign
I think which operation they prefer depends on the vendor.
https://knowledge.verisign.com/support/ … 3035718053
For the sake of security though, it certainly wouldn't hurt to generate a new private key and csr, and then have that csr signed. (option c above)
another relevant link: http://serverfault.com/questions/42993/ … ith-apache
apparently verisign does allow option a (see last comment on serverfault page)
"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍
Offline
Thanks, I went with option B.
"Oh, they have the internet on computers now."
Offline
Pages: 1