I accidentally started a rekey for an SSL certificate, and the previous certificate is scheduled to be revoked after the 72-hour replacement window. We have too many systems and client applications using the certificate to update them all within that timeframe. Has anyone successfully convinced GoDaddy to cancel or delay the revocation, or is there another way to keep the existing certificate trusted while we complete the rollout?
4 Answers
You may need to issue a new certificate from another provider or use an automated service such as Let's Encrypt, then deploy it wherever the current certificate is installed. This may be faster than waiting for a support exception, although compatibility and validation requirements should be checked first.
A rekey is generally intended to replace the old certificate, so once the revocation process has started there usually isn't a customer-side way to undo it. Keep escalating through GoDaddy support and specifically request someone from certificate operations or a senior support tier, but there is no guarantee they can stop it.
The larger issue is the deployment process. Certificate lifetimes are getting shorter, so a manual rollout that takes several days will become increasingly risky. Set up centralized certificate management, inventory every system that uses the certificate, and automate renewal and installation wherever possible.
If the old certificate is revoked, browsers and other TLS clients may reject it even if its expiration date has not passed. Treat the revocation as something that could affect every application using it, and prepare a replacement rather than relying on the old certificate remaining usable.
That is my concern as well. The certificate is used by client applications, so I need to understand the impact before the revocation takes effect.

I contacted support, but so far I have only reached first-line agents who could not give a definite answer. I have asked for a manager or higher-tier certificate support.