AutoCSR File Unlock Code

When you submit an order for an SSL Certificate from Trustico® without providing your own Certificate Signing Request (CSR), the AutoCSR service generates a Certificate Signing Request (CSR) on your behalf.

AutoCSR is a convenient option that means you will not require technical knowledge to complete your SSL Certificate order as Trustico® handles the technical aspects for you. Learn About Certificate Signing Requests (CSR) 🔗

Tip : It is highly recommended that the Certificate Signing Request (CSR) is generated using the normal processes available via your server, control panel, or hosting account. This ensures your Private Key remains under your direct control at all times.

For your security, Trustico® delivers your Private Key in a password-protected archive file. The archive cannot be opened without the correct unlock code.

What You Need

To access your Private Key, you will need three things : the encrypted ZIP file delivered with your order confirmation, your unlock code available in your order details, and compatible ZIP software installed on your computer.

Your Private Key archive uses AES-256 encryption, the industry-standard encryption method that provides strong security for your Private Key file.

The file name inside the archive is visible, but the contents of your Private Key are encrypted and require your unlock code to access.

Accessing Your Unlock Code

Your unlock code is not included in fulfilment notifications for security reasons. Instead, you will find your unlock code within your order details in your customer account.

To retrieve your unlock code, log in to the Trustico® ordering system at account.trustico.com, navigate to your order history, and select the relevant order. If applicable, your unlock code will be displayed within the order status page.

Your Order History

Access your order details to retrieve your unlock code.

Important : The unlock code is generally available for seven days only from when your order is processed. Obtain your Private Key and all installation files as soon as you receive notification that they are available.

Compatible Software for Windows

Windows File Explorer cannot extract AES-256 encrypted archives. You can browse the contents but cannot view or extract the files. You must use 7-Zip or WinZip to extract your Private Key.

The recommended option for Windows users is 7-Zip, which is free and available from 7-zip.org. After installing 7-Zip, right-click the ZIP file, select 7-Zip, then Extract files, and enter your unlock code when prompted.

WinZip is an alternative paid option available from winzip.com. Only recent versions of WinZip support AES-256 encryption.

Compatible Software for macOS

The recommended option for macOS users is The Unarchiver, which is free and available from theunarchiver.com or the Mac App Store. After installing The Unarchiver, double-click the ZIP file and enter your unlock code when prompted.

Keka is an alternative free option available from keka.io. Drag and drop the ZIP file onto Keka and enter your unlock code when prompted.

Compatible Software for Linux

The standard Linux unzip command does not support AES-256 encryption. You must use 7-Zip (p7zip) or PeaZip to extract your Private Key.

The recommended option for Linux users is 7-Zip (p7zip), which can be installed via your package manager using the command sudo apt install p7zip-full. To extract the archive, use the command 7z x filename.zip and enter your unlock code when prompted.

PeaZip is an alternative free option available from peazip.github.io that provides a graphical interface for extracting encrypted archives.

Step-by-Step Instructions

Locate the encrypted ZIP file that was delivered with your order confirmation and save it to your computer.

Get your unlock code from your order details at account.trustico.com.

Install compatible software from the recommendations above if you do not already have it installed.

Extract the archive using the software and enter your unlock code when prompted.

Save your Private Key file in a secure location and create a backup.

Security Recommendations

Keep your unlock code secure and do not share it with anyone who does not require access to install your SSL Certificate.

Store your Private Key safely and back it up in a secure location that you control.

Warning : Do not share your Private Key outside your organization or with anyone who does not need it for SSL Certificate installation. A compromised Private Key allows unauthorized parties to impersonate your website or decrypt traffic intended for your server.

Delete the Private Key from temporary folders after securing it in your permanent storage location.

Troubleshooting

If you receive a "Cannot extract files" or "Wrong password" error, verify that you copied the unlock code exactly as it is case-sensitive. Ensure you are using compatible software such as 7-Zip, WinZip, The Unarchiver, or similar. Remember that Windows Explorer cannot extract AES-256 encrypted files and you must use 7-Zip instead.

If you receive an "Archive is corrupted" error, try a different extraction tool. If the problem persists and your archive file cannot be extracted, you will need to reissue your SSL Certificate to obtain a new Private Key. Trustico® does not retain copies of Private Keys after delivery.

If you cannot find your unlock code, visit account.trustico.com and log in with your account credentials. Locate your order number in your order history and the unlock code will be displayed in the order details.

If you have lost the archive file itself, you will need to reissue your SSL Certificate. Trustico® does not store your Private Key and cannot provide a replacement.

After Seven Days

For security reasons, the unlock code is generally only displayed for a limited time. After this period, reissuing your SSL Certificate will be required in most cases.

Important : When credentials have been created and subsequently expired, they cannot be regenerated. This is an essential security measure because credentials should ultimately only exist in your possession.

To streamline the installation process, timely action is required when initially placing an order. It is strongly recommended to obtain all installation files and credentials as soon as you receive a notification that they are available.

If you have lost access to your credentials and the seven-day window has passed, proceed to reissue your SSL Certificate with a new Certificate Signing Request (CSR).

Access the tracking system to reissue your SSL Certificate.

Tracking & Management Reissue Information

Your Certificate Authority (CA) Reference number is required to access the tracking system. Learn About Reissuing Your SSL Certificate 🔗

Why This Matters

The files generated during the Certificate Signing Request (CSR) process are fundamental to your SSL Certificate security. If the credentials protecting those files were to be compromised, your encrypted communications could be at risk.

The Trustico® delivery process is designed to ensure that only you have access to these sensitive materials.

This service is provided as a courtesy. If you lose access to your protected files, or are unable to obtain or unlock them, you will be required to generate a new Certificate Signing Request (CSR) and reissue using standard processes. Explore SSL Certificate Installation Instructions 🔗

Most Popular Questions

Learn how to access and unlock your Private Key file when using the Trustico® AutoCSR service, including compatible software recommendations and troubleshooting steps.

What Does the AutoCSR Service Do and When Should You Use It?

The AutoCSR service generates a Certificate Signing Request (CSR) on your behalf when you submit an SSL Certificate order without providing your own CSR. Trustico® handles the technical aspects, so you do not need technical knowledge to complete your order.

Where Do I Find the Unlock Code for the Private Key Archive?

Your unlock code is available in your order details within your customer account. Log in to the Trustico® ordering system at account.trustico.com, navigate to your order history, and select the relevant order to view your unlock code.

Why Can't I Open the Private Key ZIP File With Windows Explorer?

Windows File Explorer cannot extract AES-256 encrypted archives. You must use compatible software such as 7-Zip (free from 7-zip.org) or WinZip to extract your Private Key file.

What Software Do I Need for Extracting the Private Key on macOS?

For macOS, Trustico® recommends The Unarchiver, which is free and available from theunarchiver.com or the Mac App Store. Keka from keka.io is an alternative free option that also supports AES-256 encrypted archives.

How Long Does the Unlock Code Remain Available?

The unlock code is generally available for seven days only from when your order is processed. You should obtain your Private Key and all installation files as soon as you receive notification that they are available.

What Should I Do When Getting a 'Wrong Password' Error During Extraction?

Verify that you copied the unlock code exactly as it is case-sensitive. Ensure you are using compatible software such as 7-Zip, WinZip, or The Unarchiver, as Windows Explorer cannot extract AES-256 encrypted files.

What Happens After Losing the Private Key or When Unable to Unlock the Archive After Seven Days?

You will need to reissue your SSL Certificate with a new Certificate Signing Request (CSR). Trustico® does not retain copies of Private Keys after delivery and expired credentials cannot be regenerated for security reasons.

How Do I Extract the Private Key Archive on Linux?

The standard Linux unzip command does not support AES-256 encryption. Install 7-Zip using 'sudo apt install p7zip-full' and extract with the command '7z x filename.zip', entering your unlock code when prompted.

Why Does Trustico® Deliver the Private Key Within a Password-Protected File?

The password-protected archive with AES-256 encryption ensures that only you have access to your Private Key. This security measure protects your SSL Certificate because a compromised Private Key could allow unauthorized parties to impersonate your website or decrypt your traffic.

Ask Trustico® Assistant

For Instant Answers - Start Here When You Have a Question or Need Help

How Quickly Are SSL Certificates Issued - Domain Validation, CaaS, OV and EV Explained

How Quickly Are SSL Certificates Issued - Domai...

Understanding what happens during the issuance process helps you choose the right SSL Certificate for your timeline and avoid unnecessary delays that could impact your launch, migration, or renewal schedule.

How Quickly Are SSL Certificates Issued - Domai...

Understanding what happens during the issuance process helps you choose the right SSL Certificate for your timeline and avoid unnecessary delays that could impact your launch, migration, or renewal schedule.

DNSSEC Validation Enforcement for SSL Certificate Issuance - March 2026

DNSSEC Validation Enforcement for SSL Certifica...

Starting in March 2026, the way Certificate Authorities (CA) handle Domain Name System Security Extensions (DNSSEC) during SSL Certificate issuance is changing significantly.

DNSSEC Validation Enforcement for SSL Certifica...

Starting in March 2026, the way Certificate Authorities (CA) handle Domain Name System Security Extensions (DNSSEC) during SSL Certificate issuance is changing significantly.

SSL Certificate Validity Periods Are Changing to 200 Days

SSL Certificate Validity Periods Are Changing t...

The reduction in SSL Certificate validity periods is driven by the need to regularly confirm that the Certificate holder is still entitled to use the SSL Certificate. No new Certificate...

SSL Certificate Validity Periods Are Changing t...

The reduction in SSL Certificate validity periods is driven by the need to regularly confirm that the Certificate holder is still entitled to use the SSL Certificate. No new Certificate...

SSL Certificate Works on WWW but Not Root Domain : Troubleshooting Guide

SSL Certificate Works on WWW but Not Root Domai...

Several server configuration problems can cause SSL Certificates to work on the www version but fail on the non-www version of a domain. Understanding these causes helps identify the specific...

SSL Certificate Works on WWW but Not Root Domai...

Several server configuration problems can cause SSL Certificates to work on the www version but fail on the non-www version of a domain. Understanding these causes helps identify the specific...

Understanding SSL Certificate File Formats and Extensions

Understanding SSL Certificate File Formats and ...

SSL Certificate files can be broadly categorized into three main types based on how the data is encoded and stored. Understanding these categories will help you identify which format you...

Understanding SSL Certificate File Formats and ...

SSL Certificate files can be broadly categorized into three main types based on how the data is encoded and stored. Understanding these categories will help you identify which format you...

Understanding the AutoCSR Service for SSL Certificate Orders

Understanding the AutoCSR Service for SSL Certi...

Learn how AutoCSR works, compare it to hosting company practices, find out when automated credential generation is appropriate versus generating your own CSR. Covers security considerations including the Trustico® non-retention...

Understanding the AutoCSR Service for SSL Certi...

Learn how AutoCSR works, compare it to hosting company practices, find out when automated credential generation is appropriate versus generating your own CSR. Covers security considerations including the Trustico® non-retention...

1 / 6