If you have an active SSL certificate running on IIS 5 or IIS 6 you cannot change the key bit length without creating a new Certificate Signing Request (CSR). The problem is that you can't create a new CSR on your site that already has an active SSL certificate. There is an easy work-around to this problem. If you are using IIS 7 just create a new CSR from scratch rather than clicking the "Renew" link in IIS 7. This will allow you to generate a new CSR with a 2048-bit key size. Just...
