Cert SSL - autorenew via DigiCert or Sectigo or others
Guru Member
Hello everyone,
I recently purchased an SSL certificate, but I read about the 200-day renewal hassle that will later become 100 and then 47 days. It's a terrifying thing for manual certificate replacement, which requires the H-series firewall.How can someone get a recognized SSL certificate (on a domain of the customer's choice like *.example.com) that auto-renews automatically, certifying the customer's firewall, without losing their patience over replacing it manually?
I know that recent uOS firmware updates should have Let's Encrypt / ACME support. However, since a wildcard certificate (*.domain.com) strictly requires the DNS-01 challenge (validation via DNS TXT records), how can we properly configure the USG FLEX H to talk with external DNS providers (like Cloudflare or GoDaddy) to fully automate this without human intervention?
Thanks!
All Replies
-
Its currently only supports Let's Encrypt and even that has problems as in the way it does the challenge which I would liked changed.
I know I'm going to hate this 47 days on some of my kit that has to be done manually
I have not looked into DNS challenge as to how that works but guess that be useful for those without inbound traffic support.
0 -
It is a nonsense to have to replace MANUALLY a cert that you can buy and install on your domain, your own domain, every 47 days
Let’s Encrypt is not my solution, a wildcard with rock solid background it is
0 -
Guess you can put it in ideas
My guess is Zyxel just thought the UI to be SSL does it matter what cert it used as long as it valid and seeing as Let’s Encrypt is free do we need to support other types?
0 -
I found this one:
The problem is to have a cert that is NOT autosigned by Zyxel but it is recognized as greed when browsing, a wildcard could do that
0 -
Hi @Zyxel_Melen
I have some doubts about cert SSL applied to FWs.
These are my questions:
1. What is the exact CLI command syntax for importing a third-party PKCS#12 (.pfx/.p12) certificate on the USG FLEX H series (uOS), including any specific requirements for how the PKCS#12 file must be built (encryption method, cipher, password format) to be accepted?
2. Is there a documented REST API endpoint for uploading/importing certificates on USG FLEX / ATP (ZLD) or USG FLEX H (uOS) devices — for automation purposes, outside of the web GUI?
3. Does Nebula Smart Sync support pushing a certificate centrally to managed USG FLEX H-series devices via the Nebula Control Center, and if so, is there an API endpoint for this that could be called programmatically?
4. Is there a public roadmap or planned feature for native ACME protocol support (automatic Let’s Encrypt / third-party CA renewal) on USG FLEX, ATP, or USG FLEX H series firmware?
0 -
Hi @GiuseppeR,
Thank you for your input. I have forwarded your request to the relevant team for review.
Our team would like to discuss the matter with you in more detail. Please check your private messages.
Zyxel Tina
0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 237 Nebula Ideas
- 6.8K Security
- 740 USG FLEX H Series
- 376 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.5K Wireless
- 58 Wireless Ideas
- 7.2K Consumer Product
- 319 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.3K FAQ
- 34 Documents
- 91 About Community
- 119 Security Highlight
Zyxel Employee