Forum Discussion

eesun_276598's avatar
Sep 19, 2016

Can we just update certificate and not its key?

Hi, The certificate is going to expire. So we need to update the certificate. Do you think we still need to update its key? It looks like that the key does not have expiration. Thank you

 

7 Replies

  • The certificate is going to expire. So we need to update the certificate. Do you think we still need to update its key? It looks like that the key does not have expiration.

     

    That depends on how you renewed your certificate. Some people, generate a new pair of public/private key when they renew the certificate. In such case, the renewed certificate will be as good as a brand new certificate. In such cases, the private key will change and hence you need to import it. If you are using the same old key pair (public/private key) for the renewed certificate, then there is no need to import the key again.

     

  • It's simple, if your vendor release certificate based on your old csr, in that case just renew certificate only. If you have generated new csr then update both(key & cert) in lb.