Hacker News new | ask | show | jobs
by charcircuit 906 days ago
The private key of a cert is a secret that is not reused between certs.
2 comments

The private key is definitely reused between certs unless you go through a process of rekeying which requires a new CSR.
It's technically possible to reuse it, but letsencrypt / certbot do not reuse it by default. You have to go out of your way and do extra work to reuse a CSR when renewing a cert.
The original poster didn't mention LE or anything else that uses ACME. It's pretty easy to reuse a key in a bespoke PKI setup; the X.509 builder APIs that I've used make it trivial. Which doesn't make it a good idea, of course.
Says who?