How to Switch From an ECC-Signed Certificate to RSA

Table of Contents


DNSimple provides SSL certificates using elliptic curve (ECC) keys by default, but some situations require an RSA key as the certificate signing key. Follow the steps below for your certificate type.

Switching a Let’s Encrypt Certificate to RSA

Let’s Encrypt certificates cannot be reissued, so you will need to order a new certificate or manually renew an existing one.

Steps to get an RSA-signed Let’s Encrypt certificate
  1. Disable auto-renewal on the existing ECC certificate you want to replace.
  2. Renew the certificate if it is about to expire, or order a new certificate.
  3. On the certificate configuration page, select the radio button for the signature algorithm.
  4. Submit the order.

See our guides for ordering and renewing Let’s Encrypt certificates.

Switching a Sectigo Certificate to RSA

For Sectigo certificates, you can reissue the existing certificate with an RSA key.

Steps to reissue a Sectigo certificate with RSA
  1. Follow the process for reissuing a Sectigo SSL certificate.
  2. In the reason field, explain that you need an RSA-based certificate.
  3. Select the radio button for the signature algorithm.
  4. Provide your CSR content in the text area if you have a custom CSR.
  5. Submit the reissue request.

Reissuing a commercial cert with RSA

Next Steps

Once the new certificate is issued, you will need to configure, verify, and install it on your server:

Have more questions?

If you have additional questions or need any assistance switching from ECC to RSA, just contact support, and we’ll be happy to help.