Renewal & Reissue

Reissuing an SSL Certificate

By the Domain India teamPublished 7 min read
Knowledge base article
Contents (8 sections)

Reissuing an SSL certificate means getting a fresh certificate for the same site, usually because something changed: you added a subdomain, moved servers, or your private key was exposed. On Domain India hosting, the free certificate included with your plan is reissued by the control panel itself, at no cost. This guide covers when you need a reissue, how to do it for the free certificate, and how to rekey a certificate you bought elsewhere.

Key takeaways

For the free Let's Encrypt certificate included with your hosting, a reissue is simply a new request: on cPanel, AutoSSL makes it on its next run and support can run it for you on request; DirectAdmin issues it automatically; in Plesk, reinstall Let's Encrypt from the domain's SSL page. It is free and takes effect once the domain check passes. For a certificate bought from another provider, generate a new CSR in your panel, ask the provider to reissue (rekey), and install the new certificate with its CA bundle.

1. When you need a reissue

ReasonFree certificateCertificate bought elsewhere
You added www, a subdomain or an addon domainWait for the next AutoSSL run (cPanel) or reinstall to include itReissue with the new names, if your certificate allows extra names
Webmail or mail shows a warning (Plesk)Reinstall with webmail and mail tickedReissue including those names
The site moved to Domain India from another hostIssued once the domain points hereGenerate a CSR here and reissue
The private key was exposed or lostReissue to get a new keyGenerate a new CSR and reissue straight away
The certificate authority asks you toNot applicableFollow their instructions and reissue

2. Reissue the free certificate on cPanel

  1. Make sure every name resolves.
    Each hostname you want covered, such as www or shop, needs a DNS record pointing at your hosting. AutoSSL skips names that do not resolve to the server.
  2. Open the Status tab.
    In cPanel, go to Security › SSL/TLS Certificates and choose the Status tab. It lists every domain and subdomain on the account and shows which are covered.
  3. Let AutoSSL run.
    AutoSSL runs on its own and requests a new Let's Encrypt certificate covering the names that pass the check. There is no button to run it yourself; if you need it sooner, open a ticket with the domain name, and support can run AutoSSL for you.
  4. Check the result.
    Refresh the page, then open the site over https:// in a private window and view the certificate.

More detail is in AutoSSL in cPanel.

3. Reissue on DirectAdmin and Windows (Plesk)

  • DirectAdmin: open your domain's SSL certificates page, choose the free Let's Encrypt option again and include every hostname you need. Menu names vary between DirectAdmin versions; ask support if you can't find it.
  • Windows (Plesk): open SSL/TLS Certificates for the domain and reinstall Let's Encrypt with the domain, www, webmail and mail ticked. The full walkthrough is in installing SSL in Plesk.
  • Webuzo: ask support how to reissue on your account.

4. Why a free reissue can fail

The new request goes through the same check as the first one, so the same things block it:

  • the domain or the new hostname does not point at your hosting yet;
  • a CAA record lists only another certificate authority; add letsencrypt.org;
  • a proxy such as Cloudflare, or a redirect or security rule, stops the check reaching /.well-known/;
  • repeated failed attempts, which Let's Encrypt limits for a while.

Fix the cause first, then run the reissue once. If it still fails, open a ticket with the domain and the error.

5. Rekey a certificate you bought elsewhere

  1. Generate a new CSR and key.
    Do it in the hosting account where the site lives, so the panel keeps the matching private key. Follow how to generate a CSR.
  2. Request the reissue.
    In your certificate provider's account, choose reissue or rekey and paste the new CSR. Most providers reissue free within the certificate's term.
  3. Validate again.
    Complete the provider's domain check by email, DNS record or a file on your site.
  4. Install the new certificate.
    In cPanel, open the Installation tab of SSL/TLS Certificates and install it; cPanel pairs it with the new key. On Windows hosting, upload it in Plesk. Always add the CA bundle.
  5. Test.
    Confirm the new certificate is served, then remove the old key if it was compromised.
Use the new key, and keep it private

A reissued certificate only works with the private key made alongside the new CSR. If installation says there is no matching key, the CSR was generated somewhere else; make a new one in this account and reissue again. Never send the private key to a provider or to support.

6. Reissue or renewal?

QuestionReissueRenewal
What changesThe key or the list of namesThe expiry date moves forward
Free certificateFree, run it yourselfAutomatic
Certificate bought elsewhereUsually free with your providerPaid to your provider
New CSRYesRecommended

For renewals, see renewing SSL certificates. Domain India doesn't sell SSL certificates, so a reissue of a paid certificate is always done with the certificate authority that sold it.

7. SSL on Domain India hosting

Almost every Domain India hosting plan includes free SSL, and on cPanel AutoSSL handles issuing, reissuing and renewing it. Domain India doesn't sell paid certificates; one you bought elsewhere can be installed on your hosting. Compare plans on cPanel hosting and DirectAdmin hosting.

Frequently asked questions

How do I reissue the free SSL certificate on cPanel?

AutoSSL runs on its own and requests a new Let's Encrypt certificate for every domain and subdomain on the account that points at the server. You can't run it yourself; open a support ticket with the domain name and support can run it for you. Check the result on the Status tab of Security › SSL/TLS Certificates.

Does reissuing the free certificate cost anything?

No. The free Let's Encrypt certificate included with Domain India hosting can be reissued as often as you need, within Let's Encrypt's limits on repeated failed attempts.

Why is my new subdomain not covered by SSL?

The subdomain probably has no DNS record pointing at your hosting, or AutoSSL has not run since you added it. Add the record, then wait for the next AutoSSL run and check the Status tab of SSL/TLS Certificates.

I think my private key was exposed. What should I do?

Reissue straight away. For the free certificate, open a support ticket with the domain name and ask for the certificate to be replaced with a new key (AutoSSL does not replace a certificate that is still valid on its own); in Plesk you can reinstall Let's Encrypt yourself. For a bought certificate, generate a new CSR and key in your panel and ask your provider to reissue.

Why does cPanel say there is no matching private key?

The CSR used for the reissue was generated on another server or account. Generate a new CSR in the hosting account where the site lives and ask your certificate provider to reissue with it.

Ready to reissue? Open your control panel from My Hosting, read how to generate a CSR for a bought certificate, or open a ticket if the reissue fails.

Reissue not working?

Tell us the domain, the hostnames you need covered and the error you see, and our support team will check DNS and the certificate for you.

Open a support ticket

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app