Manage certificates, keys and signing requests
Understand the Certificates, Keys, Requests and Settings tabs before using a third-party certificate provider.
Where Tools → Security → SSL/TLS Certificates
Before you start
- Use this advanced workflow only if your certificate provider requires it. Let’s Encrypt setup normally does not need a manual CSR.
- A public certificate, a private key and a certificate signing request are different objects.
Steps
-
1
Use Keys to manage private keys. Never expose a private key in tickets, screenshots or shared files; do not delete a key still used by an installed certificate.
-
2
Review all names before Generate. Give the certificate authority the CSR, not your private key. Do not reuse an important password as a CSR passphrase; the form warns that it is stored in the CSR.
-
3
When the issued certificate arrives, use Installation with its matching key and CA bundle.
-
4
Use Certificates to view or upload certificates stored on the account. Uploading a CRT alone is not the same as installing it on a website.
Certificates stores CRTs; installation is a separate tab. -
5
Use Requests to generate a CSR. Select or generate the appropriate key, enter the required full domain names one per line, and complete the identity/location details requested by your certificate authority.
Requests contains the CSR form and domain-name fields. -
6
Settings controls the default key type for new certificates/CSRs. Keep the provider-recommended default unless a documented compatibility or security requirement calls for another supported type.
Settings changes the default key type for future requests.
Check it worked
- Confirm the issued certificate matches the requested names and original key.
- Check the installed certificate’s status separately; a saved CSR or uploaded certificate does not prove installation succeeded.