Forum Discussion
https key
hello , if we have to use existing website certificate and key in new load balancer . How can we get the key from webiste I have got the certificate but we dont have access of old loadbalancer from where key can be exported is there any other way to get the key
5 Replies
as the key is the way to prove you are that website there is no trick or such to get it (else everyone could just do that).
you need to get the original created one. if you cant get to the load balancer (why not?), perhaps it is on the webserver also? or it is still somewhere else were it was saved during creation.
if not then you better get a new certificate fast.
- amit_128525
Nimbostratus
thanks that was helpful , one more query , if I generate new certificate for same application which is already being used on different LB , will it not give error when we request for new certificate by submitting CSR
where do you expect an error? with the company that creates the certificates or on your clients or?
personally i dont expect an issue.
- amit_128525
Nimbostratus
We have a live site which is using certificate installed on our old LB which is in our old datacentre We are planning to migrate the website to new data centre on new loadbalancer , as prepration we want to have https certificate ready on our new site , on migration day we will just disable the rule on old load balancer and insert certificate in VS in new load balancer .
My doubt was when we ask for new certificate from service provider , I dont want them to delete the old cerificate as site is still live my understanding is each CN can have only one OU . Hope I am able to explian
- Kevin_Stewart
Employee
A few things:
-
A CSR is generated from a private key. Without access to the private key, you cannot generate a new certificate to match that private key.
-
If you don't have access to the private key, then as Boneyard stated, you need to get a new certificate and private key. Now you may not be able to get a new certificate for the SAME common name from the SAME CA, but you can certainly get a certificate from another CA vendor for the same common name. The only thing that really matters here is that the browser used to access the site explicitly trusts the issuer of your new server certificate, by virtue of its installed CA certificates.
-
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com