Unable to decode CSR data. key size may be too large.

  Print
When attempting to renew your SSL certificate you receive the error Unable to decode CSR data. key size may be too large. When you supply the CSR during the certificate enrolment.

This error occurs when the CSR request has been generated using IIS7. Windows signs the CSR request with the original keyset and certificate to verify that it is a renewal request.

However the keyset is too large for many CA systems to decode. The CA instead will verify it is a renewal by checking the common name within the certificate.

To resolve this you should instead create a new CSR request and not use the Renew option in IIS7.



Related Articles