FAQs

How to Revoke Certificate when Private Key is Compromised? 

 

Similar Questions:  

What steps should I take if my private key is leaked?  

What actions are required when a private key is exposed?  

How do I revoke and reissue a certificate after a private key compromise? 

What is the process for replacing a certificate with a compromised private key? 

Overview 

If the private key associated with your certificate is compromised, the certificate must be revoked immediately to prevent unauthorized use. 

Why is revocation critical? 

A compromised private key allows attackers to impersonate your website. 

Revoking the certificate invalidates it in browsers and prevents trust misuse. 

This step-by-step guide helps you to revoke your certificate and also reissue a new certificate with a new CSR. 

Steps to follow while revoking your certificate if your private key is compromised 

Step 1: Generate a New Private Key and CSR 

  • On your server or device:  

  • Create a new private key. 

  • Generate a new CSR (Certificate Signing Request) using the new key. 

  • Do not reuse the compromised key. 

 

Step 2: Log in to Sectigo Portal 

  • Enter your credentials. 

 

Step 3: Revoke the Compromised Certificate 

  • Go to Orders Select Certificate Revoke. 

  • Provide a reason: Private Key Compromised. 

  • Confirm the revocation request. 

 

Step 4: Request a Reissue 

  • After revocation, click Reissue. 

  • Upload the new CSR generated in Step 1. 

  • Complete domain/organization validation if required. 

  • Download and install the new certificate. 

 

Important Notes 

  • Revocation is permanent; the old certificate cannot be reinstated. 

  • Reissue is free during the certificate’s validity period. 

  • Notify your security team and update any systems using the old certificate. 

 

Best Practices 

  • Use strong encryption (RSA 2048+ or ECC). 

  • Store private keys securely (preferably in an HSM). 

 

 

Related Articles:  

Tags: 

 

 

 

 

 

 

Need assistance?

Contact our team for help with your purchase or issuing your certificate.

Live chat

Call us today