Skip to main content

Can I Change the Domain Name When Reissuing an SSL Certificate Within Its Validity Period?

After an SSL certificate is issued, many customers need to change the bound domain name due to project adjustments, domain expiration, or other reasons, and wonder whether they can directly modify the domain via "Reissue". The answer depends on the certificate type and the Certificate Authority (CA) policy. The key points are explained below:

1. Whether the Domain Can Be Changed Depends on the Certificate Type

Certificate TypeCan the domain be changed?Operational Restrictions
Single-domain certificate❌ Cannot be changedOnly binds to a single domain (e.g., racent.com); you need to purchase a new certificate.
Multi-domain certificate✔️ Domain list (SAN certificate) can be adjusted- Adding/removing/modifying domains is allowed (ownership verification required)
- The total number of domains is subject to CA limits (usually 100–250)
- Additional fees may apply, subject to the system display
Wildcard certificate❌ Cannot be changedProtects the main domain and all its subdomains (e.g., *.racent.com); the main domain cannot be changed via reissue. You need to purchase a new certificate.

2. Key Points of Certificate Authority (CA) Policies

  1. Domain Modification Permissions

    • Some CAs allow modifying the domain list of multi-domain certificates during reissue, but ownership verification for newly added domains is required.
    • The main domain (Common Name) of a certificate usually cannot be changed; a new certificate request is required.
  2. Verification Requirements

    • Newly added domains must complete Domain Control Validation (DCV) again (DNS/HTTP/email verification), with the same process as the initial application.

3. Operation Process

  1. Contact the CA or provider

    • Confirm whether domain modification via reissue is supported, and learn about relevant fees and restrictions.
  2. Submit a new CSR (if changing the main domain)

    • If you need to change the main domain, you must generate a new private key and CSR (Certificate Signing Request).
  3. Verify the new domain

    • Newly added domains must pass the CA's verification process.
  4. Reissue and deploy

    • After obtaining the new certificate, replace the old one and deploy it to the server.
Notes After Certificate Reissue:
  • Validity period remains unchanged: The validity period of the reissued certificate is the same as the original one and will not be extended.
  • Fees: Price differences must be paid for newly added domains (e.g., when upgrading from a single-domain to a multi-domain certificate).
  • Special restrictions: Types requiring strict review, such as EV certificates, usually do not support domain modification.

Summary: Domain Change Rules for Different Certificates

By certificate type

Certificate TypeCan the main domain be changed?Can the domain list be modified?
Single-domain certificateNoNo
Multi-domain certificateNoYes (verification required)
Wildcard certificateNoNo
Operational Advice

Before reissuing, be sure to confirm the policy details with the CA or provider to avoid failure caused by non-compliant processes.

By Certificate Authority (CA) policy

CAWhether domains can be changedMaximum purchasable validity period
sslTrusSupported5 years
sslTrus ProNot supported3 years
DigiCert seriesSupported but requires manual operation; you need to state the reason and submit an application3 years
GeoTrustSupported but requires manual operation; you need to state the reason and submit an application3 years
CFCANot supported1 year (3 years for Guomi (SM cryptography)/5 years for standard server certificates)
GlobalSignNot supported1 year
CertumNot supported1 year