Knowledge Base

How to revoke a certificate when the private key is compromised

Overview

By following this article, you will revoke a certificate whose private key has been compromised and reissue a trusted replacement so your site stays protected. The process has four stages: generating a new private key and Certificate Signing Request (CSR), signing in to the Sectigo portal, revoking the compromised certificate, and requesting a reissue with the new CSR. It also explains how to confirm the revocation succeeded and how to protect your new key. This guidance is for certificate owners and administrators who manage certificates in the Sectigo portal.

Why revoking a compromised a private key matter

A compromised private key lets an attacker impersonate your website and decrypt protected traffic. Revoking the certificate marks it as untrusted so browsers reject it, which stops the misuse. Revocation is permanent — the old certificate cannot be restored — so you replace it by reissuing a new certificate with a new key and CSR.

Prerequisites

  • Access to your server or device to generate a new private key and CSR.

  • Sign-in credentials for the Sectigo portal.

  • Permission to manage the affected certificate order.

Steps to revoke and reissue your certificate

  1. Generate a new private key and CSR. On your server or device, create a new private key, then generate a new Certificate Signing Request (CSR) from that key. Do not reuse the compromised key.

  1. Sign in to the Sectigo portal. Go to the Sectigo login page and enter your credentials.

  1. Revoke the compromised certificate. Open Orders, select the affected certificate, and choose Revoke. Set the reason to Private Key Compromised, then confirm the request.

  1. Request a reissue. After revocation, select Reissue, upload the new CSR from step 1, complete domain or organization validation if prompted, then download and install the new certificate.


How to verify success

  • In the Sectigo portal, open the certificate order and confirm its status shows Revoked.

  • Confirm the reissued certificate shows an active/issued status and is installed on your server.

Important notes

  • Revocation is permanent; the old certificate cannot be reinstated.

  • Reissue is free during the certificate’s validity period.

  • Notify your security team and update any systems that use the old certificate.

Best practices for your new key

  • Use strong encryption: RSA (Rivest–Shamir–Adleman) 2048-bit or higher, or ECC (Elliptic Curve Cryptography).

  • Store private keys securely, preferably in a Hardware Security Module (HSM).

Similar questions

  • What steps should I take if my private key is leaked?

  • What actions are required when a private key is exposed?

  • How do I revoke and reissue a certificate after a private key compromise?

  • What is the process for replacing a certificate with a compromised private key?

Need assistance?

Contact our team for help with your purchase or issuing your certificate.

Live chat

Call us today