<div dir="ltr"><div dir="ltr"><br></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Sat, May 24, 2025 at 12:06 PM Tim van Dijen via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:</div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div><blockquote type="cite"><pre></pre>
    </blockquote>
    <p><span style="white-space:pre-wrap">This assumes self-signed certificates, because no public CA will ever allow the re-use of a private key.</span></p></div></blockquote><div><br></div><div>While there is a legitimate debate about the wisdom of reusing private keys, I have yet to meet a CA that checks for the reuse of a private key under normal renewal conditions.  (Use and reuse of "known compromised" keys being the primary exception.) </div><div><br></div><div>At least one big public CA has a "renew certificate" button in their interface that does not require any new information before issuing an updated certificate.</div><div><br></div><div>certbot has the 'reuse-key' option, which is honored by LetsEncrypt....</div><div><br></div><div>Steve.</div></div></div>