OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 16.7 Legacy Series »
  • [SOLVED] web interface SSL
« previous next »
  • Print
Pages: [1]

Author Topic: [SOLVED] web interface SSL  (Read 3792 times)

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
[SOLVED] web interface SSL
« on: July 09, 2016, 03:59:45 pm »
Hi Guys,
is it possible to create a trusted certificate with the firewall FQDN on it ?
so when the users go to the http://FQDN or https://FQDN will be secure signed.

thank you
« Last Edit: July 11, 2016, 10:58:10 am by franco »
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

bartjsmit

  • Hero Member
  • *****
  • Posts: 1595
  • Karma: 167
    • View Profile
Re: web interface SSL
« Reply #1 on: July 10, 2016, 06:30:12 pm »
Yes, I use a StartSSL certificate for the FQDN. https://www.startssl.com/

Bart...
Logged

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: web interface SSL
« Reply #2 on: July 11, 2016, 01:30:28 am »
Thank you for your answer Jan,
the firewall is not facing the internet, and the access to the firewall is always over the LAN or VPN.
using the self sign certificate gonna be a issue for the security ?
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

bartjsmit

  • Hero Member
  • *****
  • Posts: 1595
  • Karma: 167
    • View Profile
Re: web interface SSL
« Reply #3 on: July 11, 2016, 10:56:20 am »
No security risk at all, just a hassle with having to distribute the certificate to all internal clients or having your users click through warnings - which is a bad precedent.

StartSSL will verify that you own the domain through a web page or through email (e.g. hostmaster@firewall.domain). That means that you must control a website or MX record to get the cert.

Bart...

Logged

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: [SOLVED] web interface SSL
« Reply #4 on: July 12, 2016, 07:21:27 am »
thank you bart,
we know starts already using it for our exchange.
a big thank you man
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 16.7 Legacy Series »
  • [SOLVED] web interface SSL
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2