How do I transfer an SSL certificate to a new host?
What moves and what does not
The certificate is a public document that names your domain and is signed by a certificate authority. The private key is the secret half that proves you control the certificate. A new host can use the same certificate only if it also gets the private key, which you should send through a secure channel.
Some hosts and control panels offer one-click import or migration tools. Others accept only a fresh certificate request. Either way, the domain names on the certificate must match the site you run, and the certificate must not be expired.
- The certificate file, chain file, and private key are the main pieces
- Domain names on the certificate must match the new site
- Expired certificates cannot be reused
- Wildcard certificates cover subdomains at one level only
Steps for a clean move
Copy the files from the old server, then install them on the new one. Test with a browser and an SSL checker before you change DNS or move traffic. Keep the old server running until the new certificate is confirmed to work.
If you cannot locate the key, request a new certificate on the new host. The host will generate a new key and certificate signing request, and you will validate the domain again through the certificate authority. Plan some extra time for validation.
Security tips
Never paste private keys into email or public chat. Delete temporary copies after installation, and keep the key file readable only by the web server user. Note the expiration date so renewal does not catch you off guard.
Common mistakes
- Sending the private key through unencrypted email or a public file share.
- Assuming validation for a new certificate is instant, so starting the switch too late.
- Forgetting the chain file, which causes browser warnings on some devices.
