Can I prevent the old SSL certificate from being revoked after an accidental rekey?

0
0
Asked By MellowPine47 On

I accidentally rekeyed an SSL certificate and now have a 72-hour window to deploy the replacement. It is physically impossible to update every system using the certificate within that timeframe. Is there any way for the certificate authority to cancel or delay revocation of the previous certificate, or extend the replacement period? I am especially concerned about whether revocation will cause browsers and client applications to reject the old certificate before it naturally expires.

4 Answers

Answered By QuietHarbor9 On

A rekey is intended to replace the existing certificate, so revocation of the old one is generally part of that process. The certificate authority may be able to intervene in an exceptional case, but there is no guarantee. Keep escalating through their support channels and ask specifically whether the revocation can be canceled or delayed.

Answered By SilverMaple38 On

If the provider cannot stop the revocation, the practical options are to deploy the replacement as quickly as possible, obtain a new certificate if necessary, and identify every dependent system that needs updating. The most reliable answer has to come from the issuing provider because revocation behavior and reversal policies differ.

Answered By CopperVale22 On

If the old certificate is placed on a revocation list, clients that check certificate status can reject it even if its expiration date has not passed. In that case, buying another certificate does not necessarily preserve the old one; you need confirmation from the certificate authority about its revocation status and whether they can reverse the action.

MellowPine47 -

That is my concern too. The systems involved are not all under one deployment process, so replacing the certificate within 72 hours is difficult.

Answered By BrightCedar61 On

This is also a warning sign that certificate deployment needs to be automated. Public certificate lifetimes are getting shorter, so manual rotation across many systems will become increasingly difficult. Consider automated issuance and renewal, such as ACME with a suitable certificate provider, and deploy certificates through configuration management or a centralized platform.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.