Jump to content

Recommended Posts

Posted

I don't know, but I need to find out.

 

The best I could come up with was from Janet, but the wildcard cert I need seems to cost an arm and a leg.

Posted

I'd second the remote.school.county.sch.uk - there's no need for a "www"

 

We bought our certs through GoDaddy who (for what I've used them for) were fine once I'd explained how the school.county.sch.uk thing works.

Posted

Sorry, I meant it without the www - yes, I want a certificate for remote.school.county.sch.uk

 

I'll try GoDaddy, thanks. I used them at my last school and was impressed.

Posted
Alternatively, do I actually need a new SSL certificate? People are used to getting errors when using RM EasyLink anyway, so does it matter if they get one when using HAP?
Posted

I used startssl and it is free. The way to get your county subdomain (mine is school.bham.sch.uk) to get your version of bham.sch.uk in the list email tech support and say please. It's all I did and within the day they had added it to the list and I was good to go. Also it is preferred to a cert for hap.

 

Hope that helps.

  • Thanks 1
Posted

I ordered my SSL certifcates via the SWGfL deal with Janet.

 

Although they are used to it @enjay having a certificate does cut down on the screen clicks they have to do. We got the certificate to cover our whole intranet subdomain, as well as another one for our RDP gateway server

Posted
Alternatively, do I actually need a new SSL certificate? People are used to getting errors when using RM EasyLink anyway, so does it matter if they get one when using HAP?

 

Why isn't RM Easylink using a valid cert?

 

edit: OK, of the first 40* sites on Google for "RM Easylink" 35 have invalid certs (expired, internal CA, misconfigured chain or some combination of) and 5 have valid certs. Are these setup improperly by RM from the start?

 

--

 

Use a valid SSL cert because the money you save on not buying one is lost in the "it says the cert is invalid" support calls and queries. Not to mention you're adding unnecessary steps in order to use a service and teaching end-users to ignore SSL warnings.

 

*I got bored after 40.

Posted
Why isn't RM Easylink using a valid cert?

 

I think it is because the certificate has the server's internal name on it, e.g. sch-sr-001, not a public-facing remote.school.county.sch.uk

Posted

When RM launched Easylink back in the early 2000's, most browsers did not care if the certificate was self signed, and there was a link on the page for them to download and install the certificate on their own workstation.

 

Most sites continued to use the self certified certificate as the same one is used for the RMMC on the network and setting up multi-homed self certified ones was a complete pita.

Posted
I used startssl and it is free. The way to get your county subdomain (mine is school.bham.sch.uk) to get your version of bham.sch.uk in the list email tech support and say please. It's all I did and within the day they had added it to the list and I was good to go.

 

No such like. StartSSL want to charge me $59 to check my identify and another $59 to check my organisation, and I need to get County to sign something and send it off saying that I am responsible for school.county.sch.uk

 

Surely I'm not the first person with a school.county.sch.uk domain who wants to install HAP - how did the rest of you get round this?

  • 3 months later...
Posted
Necrothread ;) We asked nicely and StartSSL put ours (northants.sch.uk) in the list. However, we're looking at wildcards now to cover us for the future and StartSSL looks less and less promising as time goes on. In fact, as it's ordering page gives us an SSL error and doesn't load (lol?) we've decided to give it a well deserved wide berth and are looking to pay instead. Waiting for a reply from GoDaddy but perhaps more input would be appreciated.
Posted
We went direct to JANET.

 

Ditto. Well, we got it via our local authority from JANET (they're supposed to service geographical area, and not just state schools from what I have been told).

Posted (edited)

Looks like we're going GoDaddy. JANET refused to speak to us pretty much - the impression I got was they're rather in the dark ages. (May have misunderstood their email). If it's not from an RBC or LA they're not interested. LA, here? No check. RBC? No check. Have to be part of an organisation - check, well, not as far as they're concerned. Not to worry.

 

For startSSL, their login page on any browser is showing SSL errors :D It looks like they're going under some changes, they certainly need some.

Edited by synaesthesia

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...