Skip to main content

Update the CSR on a pending certificate order

Replace the certificate signing request (CSR) on a pending TLS or secure email certificate order before DigiCert issues the certificate.

Before you begin

  • You can only update the CSR on a pending certificate order. Once DigiCert issues the certificate, the CSR cannot be changed.

  • The replacement CSR must use a key size of 2048-bit or larger.

  • For secure email certificates: you can only update the CSR if a CSR was provided when the order was submitted. If the order was submitted without a CSR, wait for the browser-based generation email.

Notice

For your certificates to remain secure, they must use a 2048-bit or larger key size. DigiCert TLS and secure email certificates support RSA 2048, 3072, and 4096-bit keys and ECC P-256 and P-384 keys.

Update the CSR

For Enterprise, Partner, and Legacy accounts:

  1. In the CertCentral menu, go to Certificates > Orders.

  2. Select the order number for the pending certificate.

  3. On the Order details page, on the Details tab, in the Certificate status section, under What do you need to do, select the Upload CSR icon.

  4. In the Upload CSR window, upload your CSR file or paste the CSR text into the Add your CSR box.

  5. When copying from a CSR file, include the -----BEGIN NEW CERTIFICATE REQUEST----- and -----END NEW CERTIFICATE REQUEST----- tags. Select Upload.

For Subscription accounts:

  1. In the CertCentral menu, go to My Digital Trust Products > Certificates.

  2. Select the order number for the pending certificate.

  3. Follow steps 3 through 6 above.

DigiCert uses the public key from the new CSR to generate your certificate.

What's next

Edit common name and SANs on a pending order if the domains on the pending order need to be updated before issuance