Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

We have a school .co.uk domain, which is hosted with an external hosting provider. At the moment we have:

 

http://sub.domain.co.uk set to redirect to https://IPAddress:Port/Folder

 

So when the user browses to the domain, it just forwards them onto the IP of the server (which we host internally at school). I'm trying to get a certificate for this server, but it won't allow me to get a certificate for an IP address.

 

I need to somehow link the domain to the IP (and rest of the address - it's not just an IP as you can tell, it's a port and a folder too) so I can install a certificate for it.

 

Anybody got any ideas how I can achieve this?

Posted
You cannot in your current setup, because DNS (quite rightly) doesn't know about ports, protocols or URIs - only names.

 

You'll have to change your internal hosting to a standard port or live with having https://sub.domain.co.uk:Port as your address (why the port, anyway? this is what IANA's well-known ports are for).

 

Being an RM network, the default port for SSL of 443 is used for EasyLink - so we have to choose a different one for this (as we only have one outward facing IP address). Guess we can't have a trusted certificate for this then, and will just have to stick to using a self-signed :(

Posted
Can your external provider host a reverse proxy for you over a self-signed certificate, then re-certify it to send to the destination?

 

That's got to be the most confusing sentence I've read in my entire life! :)

Posted
That's got to be the most confusing sentence I've read in my entire life! :)

 

;)

 

Request -> external provider:443 -> your box:someport

Response -> your box:someport -> external provider:443 -> destination

 

where traffic between you and your provider is protected by a self-signed, and between them and the client over a properly-named one.

Posted

Ok, got this working people! :)

 

Created certificate (90 day trial from Comodo) for sub1.domain.co.uk. Installed this certificate on the server. Then went into CPanel where the domain name is hosted, and created a DNS (instead of the redirect I had in place) record for:

 

sub1.domain.co.uk --> IPAddress

 

So sub1.domain.co.uk can be browsed to, and the address actually stays as sub1.domain.co.uk instead of changing to the IP address. This means that the certificate actually matches the DNS records now for this server.

 

Thing is, sub1.domain.co.uk:1590/folder is where we need to get to, so I created another sub domain called sub2.domain.co.uk which does a simple redirect to sub1.domain.co.uk:1590/insight

 

Now the user just needs to enter sub2.domain.co.uk and it will get them to where they need to be, fully certified.

 

Gonna be a pain updating the helpdesk call with this info - might just copy and paste what I said here lol :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...