Skip to content

Manage certificates, keys and signing requests

Understand the Certificates, Keys, Requests and Settings tabs before using a third-party certificate provider.

Where Tools → Security → SSL/TLS Certificates

Before you start

  • Use this advanced workflow only if your certificate provider requires it. Let’s Encrypt setup normally does not need a manual CSR.
  • A public certificate, a private key and a certificate signing request are different objects.

Steps

  1. 1

    Use Keys to manage private keys. Never expose a private key in tickets, screenshots or shared files; do not delete a key still used by an installed certificate.

  2. 2

    Review all names before Generate. Give the certificate authority the CSR, not your private key. Do not reuse an important password as a CSR passphrase; the form warns that it is stored in the CSR.

  3. 3

    When the issued certificate arrives, use Installation with its matching key and CA bundle.

  4. 4

    Use Certificates to view or upload certificates stored on the account. Uploading a CRT alone is not the same as installing it on a website.

    Certificates stores CRTs; installation is a separate tab.
  5. 5

    Use Requests to generate a CSR. Select or generate the appropriate key, enter the required full domain names one per line, and complete the identity/location details requested by your certificate authority.

    Requests contains the CSR form and domain-name fields.
  6. 6

    Settings controls the default key type for new certificates/CSRs. Keep the provider-recommended default unless a documented compatibility or security requirement calls for another supported type.

    Settings changes the default key type for future requests.

Check it worked

  • Confirm the issued certificate matches the requested names and original key.
  • Check the installed certificate’s status separately; a saved CSR or uploaded certificate does not prove installation succeeded.