
Choose or manage the certificate based on the hostnames you need to protect, the validation level, the server platform and whether you control DNS. Keep the private key secure, complete validation, install the full certificate chain and verify the live HTTPS connection before relying on the certificate.
· Identify every hostname the certificate must cover.
· Confirm that you control DNS or the required validation channel.
· Generate and securely retain the private key when a CSR is required.
Why would I need to reissue my certificate? An SSL reissue is done to keep your site secure and private if it is moved, or some information on your SSL was changed. The reissue allows you to get a brand-new certificate code. The most typical reasons for certificate reissuance are: The existing certificate cannot be installed on the server.
For example, if the Private key (RSA Key) is lost/deleted or a "modulus mismatch" error appears during installation; The website has been moved to another web hosting server; Changing the hostnames secured by the certificate; Changes made to the organization details listed in the OV/EV certificate (only within 45 days since the initial certificate issuance); Use the remaining validity of your SSL if you purchased it for 2-5 years.
Open the HTTPS site from a clean browser session and inspect the certificate subject, SAN hostnames, issuer, validity dates and chain. Test every hostname covered by the certificate and confirm that HTTP redirects behave as intended.
· DNS validation records are missing, incorrect or added at the wrong DNS provider.
· The certificate does not include the hostname being opened.
· The private key does not match the certificate or CSR.
· The server is missing an intermediate certificate or is still presenting the old certificate.
Can I reuse the same certificate after moving servers?
Often the certificate can be reinstalled if you still have the matching private key and the certificate remains valid. Reissue it when the key, CSR or certificate details must change.
Why does the browser still show the old certificate?
The server or load balancer may still present the old certificate, another virtual host may be selected, or an intermediate cache may not have reloaded the configuration.
When should I submit a ticket?
Submit a ticket when validation remains pending after the published records are visible, or when the NiceNIC order does not provide the expected certificate files.
- How to Generate a CSR Code
- How to Activate and Download an SSL Certificate
- How to verify certificate installation correctly
- How to choose an SSL certificate
If the issue continues after you complete the checks above, submit a NiceNIC support ticket with the affected domain or product, the exact error message, the time of the issue and the troubleshooting already completed.