Hello,
We are coming up to our certificate renewal, and I noticed that the BeyondTrust documentation states “You do not need to create a new certificate request”, and to provide the original CSR if the CA doesn’t already have it.
See DigiCert documentation, “Best practice is to generate a new CSR when renewing your SSL/TLS certificate. This creates a new, unique keypair (public/private) for the renewed certificate.”
Why would BeyondTrust, a company developing security products, recommend a less secure process? Am I misunderstanding something, or should the BeyondTrust documentation follow industry best practices for renewing certificates which is to generate a new CSR in order to create a new keypair?