Knowledge Base
What to Do If the Private Key of Your Sectigo Certificate Is Missing
Overview
By the end of this article, you will know why a missing private key cannot be recovered and how to restore a working certificate by requesting a reissue. The article first explains what a private key is and why Sectigo cannot retrieve it, then walks through the reissue procedure using a new Certificate Signing Request (CSR) generated from a newly created private key. It then covers how to verify that the reissued certificate is installed correctly, common issues you may encounter during reissue, and best practices for storing private keys, including secure backup and the use of a hardware security module (HSM), so the same loss does not happen again.
What Is a Private Key?
A private key is a unique cryptographic file created on your server or device at the moment you generate a Certificate Signing Request (CSR). The certificate Sectigo issues is mathematically paired with that specific private key. Without the matching private key, the certificate cannot be installed or used to secure a connection, even though the certificate file itself is still valid.
Sectigo never receives or stores your private key. The key stays on your system for security reasons, so Sectigo cannot recover, resend, or regenerate it. If the private key is lost, deleted, or overwritten, the only supported resolution is to reissue the certificate using a new Certificate Signing Request (CSR).
Prerequisites
Before you begin, make sure you have:
- Access to the server or device where the certificate will be installed, with permission to generate a new private key and Certificate Signing Request (CSR).
- Login credentials for your Sectigo account at store.sectigo.com.
- The order number or details of the certificate you need to reissue.
- The ability to complete validation, such as access to the domain's administrative email address or permission to add a Domain Name System (DNS) record.
Steps to Reissue a Certificate When the Private Key Is Missing
- Generate a new Certificate Signing Request (CSR) on your server, using a newly created private key. Keep the new private key file in a safe location on the server.
- Sign in to your Sectigo account at store.sectigo.com.
- Locate the affected certificate order and submit a reissue request, pasting in the new Certificate Signing Request (CSR).
- Complete all validation steps that Sectigo requests for the certificate type. Validation must finish before the reissued certificate is delivered.
- Download and install the reissued certificate on your server, then pair it with the new private key you created in step 1.
Reissuing does not change the expiry date of your certificate, and there is no additional cost for a reissue within the certificate's validity period.
How to Verify Success
To confirm the reissue worked:
- Restart the web server or service, so the new certificate and private key are loaded.
- Open the site in a browser using HTTPS and check that the padlock appears with no certificate warning.
- View the certificate details in the browser and confirm the issue date matches your reissue, not the original order.
- If your server offers a key-match check, confirm the installed certificate and the private key report as a matching pair.
Troubleshooting
Issue
The server reports that the certificate and private key do not match.
Cause
The reissued certificate was paired with the old private key, or with a key from a different Certificate Signing Request (CSR).
Solution
Reinstall the reissued certificate using the private key that was created alongside the new Certificate Signing Request (CSR) in step 1.
Issue
The reissued certificate has not been delivered.
Cause
Validation for the domain or organization is still pending.
Solution
Check your Sectigo account for outstanding validation tasks, complete them, and allow the validation to process before retrying the installation.
Tips and Best Practices for Protecting Private Keys
- Back up the private key to an encrypted location, or store it in a hardware security module (HSM), immediately after installation.
- Use a strong password when exporting a certificate and key in .pfx or a similar bundled format.
- Never place private keys in public code repositories, shared drives, or unsecured messaging channels. A key that is exposed is treated as compromised and the certificate must be revoked and replaced.
- Record where each private key is stored, so the file can be located when the certificate is renewed or moved to a new server.
Similar Questions
- How do I recover a lost private key for my Sectigo certificate?
- What are the steps to reissue an SSL/TLS certificate with a new Certificate Signing Request (CSR)?
- Can Sectigo resend or restore my private key?
- Why does my server say the certificate and private key do not match?
- How do I back up a private key safely?
Need assistance?
Contact our team for help with your purchase or issuing your certificate.