Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mihirk
New Contributor

SSL Certificate w/ FortiDDNS?

First time poster here.

 

I've setup VPN recently and unfortunately our webhost does not do masked subdomain forwarding so I was thinking of using FortiDDNS to at least make it easy to get to the portal.

I've basically xxx.fortiddns.com:1020 for our VPN address.

 

My question is that how would I be able to get an SSL Certificate for FortiDDNS subdomain if Certificate Authorities are going to require me to verify the domain? Would i be able to upload the .txt file for verification?

 

Also, any suggestions on how can I redirect our sub-domain to the IP:Port and mask it? so instead of the IP, they see vpn.xxx.com

 

Thank you,

MK

2 REPLIES 2
emnoc
Esteemed Contributor III

 I've setup VPN recently and unfortunately our webhost does not do masked subdomain forwarding so I was thinking of using FortiDDNS to at least make it easy to get to the portal.

 

Not quite following you and maksed subdomain forwarding ? Do you have a domain under your control? Can't you just place a dns A record in ( i.e  vpn1.<yourdomain.com> and then build a CSR for that ? You can use DigiCert, Comodore or Let'sEncrypt b4 buying a certificate.

 

I done the above for customer who have portals and wanted a certificate and where either slow in getting one bought. Just be aware of the cert lifetime and digicert/comodo will only issue a cert for that domain one time. 

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
neonbit
Valued Contributor

Hi Ken, I believe he's talking about the free DDNS service provided by Fortinet. 

 

With the certificate, I'm not sure if a CA will allow you to create a certificate for it. If they only require you to add a piece of code/variable to the website then you can do this by either editing the SSLVPN default portal to add the code, or you could create an internal web server and just VIP the domain to this server hosting the code until the CA verifies it.

Labels
Top Kudoed Authors