Godaddy ssl needs 2048 bits

aitorla

New member
Joined
Aug 16, 2009
Messages
4
DA generates 1024 bit keys. I use Godaddy certificates that needs 2048bits. Where can i change it ?
I read other thread but i cant select 2048 bits certificate.

Regads,

Aitor
 
You change it when you create the csr under the user ssl section.
 
My version

DirectAdmin Values
Compiled on Redhat 9.0
Server Version 1.34.4
Current Available Version 1.344000
Last Updated Tue Dec 8 21:28:17 2009
Update DirectAdmin
 
This has been discussed previously. To delete the 1024-bit private key you must first use DirectAdmin to create a self-signed certificate, choosing a 2048-bit private key. This will replace the internal 1024-bit private key. Then go through the Certificate page again, this time selecting a CSR. This will use the 2048-bit private key to build the new CSR.

Jeff
 
This has been discussed previously. To delete the 1024-bit private key you must first use DirectAdmin to create a self-signed certificate, choosing a 2048-bit private key. This will replace the internal 1024-bit private key. Then go through the Certificate page again, this time selecting a CSR. This will use the 2048-bit private key to build the new CSR.

Jeff

Jeff, this isn't working and it's still creating a new 1024 key.....

DO we need to delete the old key manually? Is this new key created created with direct admin or the command line? Because I can't see a way to specify a 2048 key under direct admin.... only manually.
 
I'm a little confused here... I have created a 2048 key for the server, for direct admin... they are both using 2048 self signed key's.

I then go to one domain to make a CSR through Directadmin and it pulls a 1024 key again and replaces the 2048 I made through ssh.

How do I resolve this please?
 
My problem was I was using the capri skin which does not have the bit choice on it.... looking for an update now.... damn thing lol
 
I found that out the hard way... but it's a nice design and customers like it much better.
 
DA generates 1024 bit keys. I use Godaddy certificates that needs 2048bits. Where can i change it ?
I read other thread but i cant select 2048 bits certificate.

Regads,

Aitor

Does any one found solution for this issue??? Need solution urgently!!!!
 
Are you using the capri skin as above?

You have not given us any information to help you. Read the thread and give us information to help you. We are not going to ask the same questions as above.
 
1) You must use a skin that supports either 1024 or 2048 bits.

2) You must create a new 2048-bit key. Creating a CSR always uses the old key. To create a new key you must first use DirectAdmin to create a self-signed Certificate, making sure to set for 2048 bits.

Once that's done you should create the CSR, making sure again to set for 2048 bits.

A bit cumbersome, but we do it almost every day.

It works.

Jeff
 
Hello,

FYI, I've addressed this issue for the next release of DA:
http://www.directadmin.com/features.php?id=1074

Keep in mind that once DA notices the bit differences, it will backup your old key and replace it with the new one, which will mean your new key and old cert won't be a valid pair, so DA will set your website to use the shared server certificate until you paste in your new cert. More info in the above link.

John
 
Thanks, John. A careful read of your new feature post indicates that anyone who wants to, and keeps a copy of the old Certificate, can still reinstall the old key and Certificate.

To me this is acceptable.

For everyone:

If you do that, be sure to save the new key; you'll have to install it again.

Note also that if you don't reinstall the old key and Certificate before you order your new Certificate, you'll probably break your Certificate Vendor's automatic extra-month(s) issue on renewal or competitive Certificate orders.

We do it this way:

We save the old key and cert.

We create the new CSR and key.

We save both.

We restore the old key and cert.

We issue the new Certificate.

When we install the new Certificate we also install the new key again at the same time.

This will keep the extra month(s) issue working.

Is this all too complicated for you? Are you afraid you'll lose the new key and need to get your Certificate reissued? Do you have problems with those pesky CA Root Certificates?

Our special offering for DirectAdmin Certificates including installation may be found here.

Jeff
 
Back
Top