ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Need SSL cert - What's next best?

    IT Discussion
    9
    38
    1.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      marcinozga @Obsolesce
      last edited by

      @obsolesce said in Need SSL cert - What's next best?:

      @marcinozga said in Need SSL cert - What's next best?:

      Can you put reverse proxy in front of that appliance and automate certs on proxy?

      Hmm, perhaps. I didn't think of that, but there are other services besides https that the proxy would need to pass through to the server then. Is that possible? Users would access the https stuff over web browser, but agents on their computers would be trying to connect to the same server.domain.com over some custom port, lets say 52274 for example.

      Yes, it can be done, with Nginx for example.

      1 Reply Last reply Reply Quote 1
      • ObsolesceO
        Obsolesce @dbeato
        last edited by

        @dbeato said in Need SSL cert - What's next best?:

        One thing, if you don't want automation but want free SSL you can use ZeroSSL
        https://zerossl.com/
        but you need to install it every 90 days since it is LE.

        That would still be an issue here. I'll just go the reverse proxy route with NGINX. Full automation with LE means zero maintenance. No automation with LE means way too much maintenance. 2-year SSL cert from somewhere else means less maintenance, but costs.

        dbeatoD 1 Reply Last reply Reply Quote 1
        • dbeatoD
          dbeato @Obsolesce
          last edited by

          @obsolesce said in Need SSL cert - What's next best?:

          @dbeato said in Need SSL cert - What's next best?:

          One thing, if you don't want automation but want free SSL you can use ZeroSSL
          https://zerossl.com/
          but you need to install it every 90 days since it is LE.

          That would still be an issue here. I'll just go the reverse proxy route with NGINX. Full automation with LE means zero maintenance. No automation with LE means way too much maintenance. 2-year SSL cert from somewhere else means less maintenance, but costs.

          Yeah, I am giving you the orher alternatives that make it so much easier to use a proxy for it.

          1 Reply Last reply Reply Quote 0
          • dbeatoD
            dbeato @Obsolesce
            last edited by

            @obsolesce said in Need SSL cert - What's next best?:

            @dbeato said in Need SSL cert - What's next best?:

            I have been using Namecheap
            https://www.namecheap.com/security/ssl-certificates.aspx

            Or Godaddy at times.

            What's their root ca?

            For Godaddy they are their own and NameCheap uses Comodo.

            1 Reply Last reply Reply Quote 0
            • stacksofplatesS
              stacksofplates
              last edited by

              Cloudflare does free SSL. That's what I used for my blog since it's GitLab pages and you can't automate the LetsEncrypt part with them. It's valid for I think 15 years.

              ObsolesceO 2 Replies Last reply Reply Quote 0
              • ObsolesceO
                Obsolesce @stacksofplates
                last edited by

                @stacksofplates said in Need SSL cert - What's next best?:

                Cloudflare does free SSL. That's what I used for my blog since it's GitLab pages and you can't automate the LetsEncrypt part with them. It's valid for I think 15 years.

                Wow really?

                I'll see if I can find that.

                scottalanmillerS 1 Reply Last reply Reply Quote 0
                • ObsolesceO
                  Obsolesce @stacksofplates
                  last edited by

                  @stacksofplates said in Need SSL cert - What's next best?:

                  Cloudflare does free SSL. That's what I used for my blog since it's GitLab pages and you can't automate the LetsEncrypt part with them. It's valid for I think 15 years.

                  It's only free for personal websites, this would be for production use.

                  0_1537558852487_1d52ae71-8507-4563-8f33-58046fc73ece-image.png

                  dbeatoD 1 Reply Last reply Reply Quote 0
                  • ObsolesceO
                    Obsolesce
                    last edited by

                    I can't just get the cert?

                    stacksofplatesS scottalanmillerS 2 Replies Last reply Reply Quote 0
                    • stacksofplatesS
                      stacksofplates
                      last edited by

                      That must be for CDN. DNS is free along with the stuff like certs.

                      1 Reply Last reply Reply Quote 1
                      • stacksofplatesS
                        stacksofplates @Obsolesce
                        last edited by

                        @obsolesce said in Need SSL cert - What's next best?:

                        I can't just get the cert?

                        You have to set your domain up in it.

                        scottalanmillerS 1 Reply Last reply Reply Quote 1
                        • dbeatoD
                          dbeato @Obsolesce
                          last edited by

                          @obsolesce said in Need SSL cert - What's next best?:

                          @stacksofplates said in Need SSL cert - What's next best?:

                          Cloudflare does free SSL. That's what I used for my blog since it's GitLab pages and you can't automate the LetsEncrypt part with them. It's valid for I think 15 years.

                          It's only free for personal websites, this would be for production use.

                          0_1537558852487_1d52ae71-8507-4563-8f33-58046fc73ece-image.png

                          Free for Business too, read the description đŸ™‚

                          1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @Obsolesce
                            last edited by

                            @obsolesce said in Need SSL cert - What's next best?:

                            I can't just get the cert?

                            They dont' provide certs, they are a CDN.

                            dbeatoD 1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @stacksofplates
                              last edited by

                              @stacksofplates said in Need SSL cert - What's next best?:

                              @obsolesce said in Need SSL cert - What's next best?:

                              I can't just get the cert?

                              You have to set your domain up in it.

                              They did this new wording a few days ago.

                              1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @Obsolesce
                                last edited by

                                @obsolesce said in Need SSL cert - What's next best?:

                                @stacksofplates said in Need SSL cert - What's next best?:

                                Cloudflare does free SSL. That's what I used for my blog since it's GitLab pages and you can't automate the LetsEncrypt part with them. It's valid for I think 15 years.

                                Wow really?

                                I'll see if I can find that.

                                You just set it up and turn your cloud orange. There is nothing to install.

                                1 Reply Last reply Reply Quote 1
                                • dbeatoD
                                  dbeato @scottalanmiller
                                  last edited by

                                  @scottalanmiller said in Need SSL cert - What's next best?:

                                  @obsolesce said in Need SSL cert - What's next best?:

                                  I can't just get the cert?

                                  They dont' provide certs, they are a CDN.

                                  They can provide you the Origin SSL cert that only works using their CDN.

                                  scottalanmillerS 1 Reply Last reply Reply Quote 1
                                  • scottalanmillerS
                                    scottalanmiller @dbeato
                                    last edited by

                                    @dbeato said in Need SSL cert - What's next best?:

                                    @scottalanmiller said in Need SSL cert - What's next best?:

                                    @obsolesce said in Need SSL cert - What's next best?:

                                    I can't just get the cert?

                                    They dont' provide certs, they are a CDN.

                                    They can provide you the Origin SSL cert that only works using their CDN.

                                    Oh, didn't know. But makes sense.

                                    JaredBuschJ 1 Reply Last reply Reply Quote 0
                                    • JaredBuschJ
                                      JaredBusch @scottalanmiller
                                      last edited by

                                      @scottalanmiller said in Need SSL cert - What's next best?:

                                      @dbeato said in Need SSL cert - What's next best?:

                                      @scottalanmiller said in Need SSL cert - What's next best?:

                                      @obsolesce said in Need SSL cert - What's next best?:

                                      I can't just get the cert?

                                      They dont' provide certs, they are a CDN.

                                      They can provide you the Origin SSL cert that only works using their CDN.

                                      Oh, didn't know. But makes sense.

                                      Not new. Had this for a while.

                                      1 Reply Last reply Reply Quote 0
                                      • ingmarkoecherI
                                        ingmarkoecher @Obsolesce
                                        last edited by

                                        @obsolesce I've had a good experience with https://www.sslpoint.com - they're not widely known but we've used them for a few certs over the last 3 years or so (mostly Exchange) and it worked well. The prices are pretty reasonable and support is great (which in most cases you probably won't need).

                                        1 Reply Last reply Reply Quote 0
                                        • PhlipElderP
                                          PhlipElder @Obsolesce
                                          last edited by

                                          @obsolesce
                                          www.gogetssl.com
                                          Cheap like borscht.

                                          1 Reply Last reply Reply Quote 0
                                          • PhlipElderP
                                            PhlipElder @Obsolesce
                                            last edited by PhlipElder

                                            @obsolesce said in Need SSL cert - What's next best?:

                                            @marcinozga said in Need SSL cert - What's next best?:

                                            Can you put reverse proxy in front of that appliance and automate certs on proxy?

                                            Hmm, perhaps. I didn't think of that, but there are other services besides https that the proxy would need to pass through to the server then. Is that possible? Users would access the https stuff over web browser, but agents on their computers would be trying to connect to the same server.domain.com over some custom port, lets say 52274 for example.

                                            Split the DNS by setting up machine.domain.com internally with a blank A record to the machine’s IP. That keeps the cert situation tidy.

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 2 / 2
                                            • First post
                                              Last post