Hightower Posted October 13, 2010 Posted October 13, 2010 We have a school .co.uk domain, which is hosted with an external hosting provider. At the moment we have: http://sub.domain.co.uk set to redirect to https://IPAddress:Port/Folder So when the user browses to the domain, it just forwards them onto the IP of the server (which we host internally at school). I'm trying to get a certificate for this server, but it won't allow me to get a certificate for an IP address. I need to somehow link the domain to the IP (and rest of the address - it's not just an IP as you can tell, it's a port and a folder too) so I can install a certificate for it. Anybody got any ideas how I can achieve this?
powdarrmonkey Posted October 13, 2010 Posted October 13, 2010 You cannot in your current setup, because DNS (quite rightly) doesn't know about ports, protocols or URIs - only names. You'll have to change your internal hosting to a standard port or live with having https://sub.domain.co.uk:Port as your address (why the port, anyway? this is what IANA's well-known ports are for).
Hightower Posted October 13, 2010 Author Posted October 13, 2010 You cannot in your current setup, because DNS (quite rightly) doesn't know about ports, protocols or URIs - only names. You'll have to change your internal hosting to a standard port or live with having https://sub.domain.co.uk:Port as your address (why the port, anyway? this is what IANA's well-known ports are for). Being an RM network, the default port for SSL of 443 is used for EasyLink - so we have to choose a different one for this (as we only have one outward facing IP address). Guess we can't have a trusted certificate for this then, and will just have to stick to using a self-signed
powdarrmonkey Posted October 13, 2010 Posted October 13, 2010 Can your external provider host a reverse proxy for you over a self-signed certificate, then re-certify it to send to the destination?
Hightower Posted October 13, 2010 Author Posted October 13, 2010 Can your external provider host a reverse proxy for you over a self-signed certificate, then re-certify it to send to the destination? That's got to be the most confusing sentence I've read in my entire life!
powdarrmonkey Posted October 13, 2010 Posted October 13, 2010 That's got to be the most confusing sentence I've read in my entire life! Request -> external provider:443 -> your box:someport Response -> your box:someport -> external provider:443 -> destination where traffic between you and your provider is protected by a self-signed, and between them and the client over a properly-named one.
webman Posted October 13, 2010 Posted October 13, 2010 The way we plan on doing this is to have the SSL cert at our reverse proxy, running on 443, handling sub.domain.net. Directories of this subdomain will then be proxied to both Easylink and the other site. https://sub.domain.net/easylink -> internally: RM server running Easylink https://sub.domain.net/otherthing -> internally: web server In theory, it should work.
Hightower Posted October 13, 2010 Author Posted October 13, 2010 Ok, got this working people! Created certificate (90 day trial from Comodo) for sub1.domain.co.uk. Installed this certificate on the server. Then went into CPanel where the domain name is hosted, and created a DNS (instead of the redirect I had in place) record for: sub1.domain.co.uk --> IPAddress So sub1.domain.co.uk can be browsed to, and the address actually stays as sub1.domain.co.uk instead of changing to the IP address. This means that the certificate actually matches the DNS records now for this server. Thing is, sub1.domain.co.uk:1590/folder is where we need to get to, so I created another sub domain called sub2.domain.co.uk which does a simple redirect to sub1.domain.co.uk:1590/insight Now the user just needs to enter sub2.domain.co.uk and it will get them to where they need to be, fully certified. Gonna be a pain updating the helpdesk call with this info - might just copy and paste what I said here lol
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now