SSL CSR generation and certificate install issue: random generated?

EVO1

Verified User
Joined
Jul 31, 2012
Messages
14
Hello,

In the proces of installing a SSL EV certificate a few unexpected things happend which left me with a few questions.

After filling in the details in "create a certificate request" I clicked the "save" button as described. There was no screen with the CSR!!

Instead there was some short message screen without details. I clicked the "home" or browser "back" button (don't remember). I returned to the SSL menu. I believe I also clicked the "paste form clipboard" in the field "Paste a pre-generated certificate and key" button once. Then I clicked the "save" button again and now a CSR window did come up! I copied the CSR request key and applied for a certificate at the supplier.

When I later returned to the SSL menu there appeared a "RSA private key" in the "Paste a pre-generated certificate and key" field which I expected but what I didn't expect was a certificate key already directly below it! I thought I had to paste that from what I will get from my supplier shortly.

Questions:

Did I generate two CSR's and private keys by hitting "save" twice? (Or: is a CSR randomly created every time you click "save" or is it coupled static with the details of the request etc?)
Is the CSR I sent to my supplier the correct one or will there be a mismatch with the private key?
Do I replace the certificate key in the field "Paste a pre-generated certificate and key" with what I get from my supplier?
Is it wise to contact the supplier and generate a new CSR before having to pay twice?

Who can help please?
 
I don't know what happened, and I'm not going to guess. What I will tell you is that can always start over and create a new CSR if you haven't sent it in, and if you have, and the resulting Certificate won't work (this generally happens if somehow you end up with a new private key (DirectAdmin tries to protect from this, but I suppose it could happen) any reputable vendor will revoke and reissue the Certificate at no charge.

(At least we will, and we're reputable :)).

Jeff
 
I contacted my vendor. I can send them a new CSR while in the process of issuing a certificate.

Because somehow "automatically" a certificate was placed I guess I accidentally made a self signed one (with its own private key) after the CSR was made. The private key belonging to the CSR maybe another then the one I see now.

I hope the CSR this time will appear after clicking the save button once! Another question in order to do it right this time: do I have to clear settings somewhere (private key / certifcate that appeared) or erase something before creating the new CSR?
 
I created a new thread for my last question (continuing problem)...
 
Once you create a private key for a domain, DirectAdmin will continue to use that key, so you can keep using your old Certificate until your new one is issued and installed (for example, if you renew in advance). To clear a private key you should create a self-signed Certificate. This will delete the old private key and create a new one.

Jeff
 
This will delete the old private key and create a new one.

Jeff

Hello Jeff, thanks. I have created a self signed certificate and after that a new CSR.

In the "paste a pre-generated certificate and key" field I still get the private key followed by a certificate code! So not only a new private key.

Question:
When I get the certificate code from my vendor: do I delete the certificate code (and leave the private key) that's now there and past the new certificate code in its place, directly below the private key? Will the private key (top part I do not delete) work with the new certificate?
 
I believe this is now the behavior of DirectAdmin; ask me again next week; in the next few days I'm going to do a Cert install for a client.

Deleting the old certificate and installing the new one should work; that's the expected behavior.

Note however that I'm happy to guarantee all my work, but can't guarantee your implementation of what I write on these forums.

Jeff
 
Problem solved. I deleted the certificate and pasted the new one directly under the private key. Also had to install two intermediate certificates and root certificate. After a few modifications on my site the whole site has an EV SSL now.

Thanks for the help!
 
And I've done the Certificate install and can also verify that it works this way.

Jeff
 
Back
Top