Skip to main content

Rekey certificates

To transition an existing certificate to a more cryptographically secure algorithm, you can rekey the certificate.

The rekeying process is designed to ensure a smooth migration while maintaining compatibility with existing systems.

Before you begin

Review the following statements before you begin to rekey a certificate:

  • The certificate must have an online status.

  • The corresponding keypair can be either online or offline; however, dynamic keypairs cannot be rekeyed.

  • To implement automatic rekeying, auto-renewal must be enabled in the certificate profile.

  • HSM does not support PQC algorithms.

    • If a rekey is initiated for an HSM keypair using a PQC algorithm, then the new keypair will be generated on disk, instead of HSM.

  • CertCentral does not support all algorithms.

    • PQC and EdDSA algorithms will not appear as options in CertCentral profiles.

  • Certificate renewal only applies to the default certificate of the production keypair.

Rekey existing certificates

  1. Sign in to DigiCert ONE.

  2. Navigate to the Manager menu icon (top-right), select Software Trust .

  3. In the left navigation menu, select Certificates > Certificate profiles.

  4. Locate and select the desired certificate profile.

  5. Select the pencil icon to edit.

  6. For Auto-renew, select Yes.

  7. For Auto-renew scope, select Apply to new and existing certificates.

  8. Select to activate Initiate re-key process upon certificate auto-renewal.

  9. Select the desired Re-key algorithm and Security level.

    • If you are using an HSM keypair with a PQC algorithm, then a warning will display.

  10. Save your changes.

Afterwards, when a certificate reaches the renewal period, will:

  • Generate a new keypair based on rekey settings.

  • Generate a new certificate using the newly created keypair.

  • Transition the keypair by renaming the new keypair to match the name of the old keypair.

Date de publication: