05-21-2015 12:56 PM
Hi, have anyone successfully installed wildcard certificate on ESA and use it for management (HTTPS) connections?
Problem is that I installed certificate on ESA, bind it to interface.
ESA is using it but browser is still complaining that name is invalid (I'm connecting to ESA with DNS name, not IP address of course).
Any idea?
05-22-2015 06:47 AM
Hi Jernej,
I'm using a wildcard certificate for TLS and admin UI. This is working like a charm.
You probably need to restart your browser.
Best regards, Matthias
05-23-2015 12:03 AM
Ken, I selected wildcard certificate.
Matthias, I reproduces error with two browsers - same result.
Wildcard certificate is in use, I've checked URL address that host part matches CN in the certificate but still same problem.
Thank you to confirm wildcard certs are supported. I'll troubleshoot further and let you know about results.
05-24-2015 08:37 PM
Hello Jernej,
I apologise if this response is late.
But on your browser, I assume it's still showing up as certificate is not trusted error?
Could you attempt to clear all cache and information within your browsers and to re-try it.
Also ensure that the certificates (I know you said you've already checked to make it in use) but also go to GUI > Network > Certificates ; ensure this certificate is showing as 'active'
Finally, if your GUI > Network > IP interfaces which are being used, ensure that if they're clustered, you're enabling the certificate to be used at the right level of configuration.
Thanks,
Matthew
05-24-2015 08:46 PM
you may need to import the whole cert chain.
I imported the cert, key, and intermediate certs to the cert store on a windows box, then exported the cert to a pfx, checking the box to export the whole chain. Then just import it to the esa.
05-22-2015 08:47 AM
Go to Network/IP Interfaces.
Click on the interface you're using for management. 6th line down lets you select the cert you want to use...
Ken
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide