Let's encrypt - SSL certificate

245

Comments

  • ItsPronouncedZyWhaaa
    ItsPronouncedZyWhaaa Posts: 2  Freshman Member
    First Comment First Anniversary
    User beware, about to start up a support ticket and dig into logs.  But after using certbot to manually create a PEM cert, then using openssl to convert it to a pfx and uploaded it to my remote USG40 successfully, as soon as I changed the WWW cert from default to my new one, the unit stopped processing traffic altogether. HTTP and HTTPS GUI access stopped, and I was only able to access via SSH.   After trying to apply lastgood.conf from a few days before, the unit locked up on reboot and I had to drive an hour to go manually power cycle.  In which case it reverted back to the current config with the broken traffic and HTTPS access.  I was finally able to get it back to normal by doing a "ip http secure-server cert default".  No idea what happened yet but totally ruined my Saturday lol.
  • Zyxel_Vic
    Zyxel_Vic Posts: 282  Zyxel Employee
    25 Answers First Comment Friend Collector Seventh Anniversary

    ItsPronouncedZyWhaaa

    Sorry for what you had sufferred, or can you PM me the cert you imported to see what's wrong in this cert?

  • StevenB
    StevenB Posts: 3  Freshman Member
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula First Comment
    Can someone provide me a manual about how to import a free ssl certificate into my USG60?
  • [Deleted User]
    [Deleted User] Posts: 118  Ally Member
    5 Answers First Comment Friend Collector Fifth Anniversary

    dear @StevenB


    here you go 

  • Dudley_Winchester
    Dudley_Winchester Posts: 22  Freshman Member
    First Comment Sixth Anniversary
    +1 for a wizard on the USG allowing easy setup with Let's encrypt.
  • Alcindo
    Alcindo Posts: 4  Freshman Member
    First Comment Sixth Anniversary
    ZyWALL's (and any other public facing IAD) should have LetsEncrypt support as standard.
    I.e. configure the FQDN of the ZyWALL. Link it to the WAN the FQDN is is on. Enable "Use LetsEncrypt certificate", press Apply. And the ZyWALL should do all of this including the periodic renewal automatically.
    This will make easy to have any ZyWALL (with a FQDN) have a valid certificate.
    Best regards,
    Alcindo
  • +1 !!!
  • dpipro
    dpipro Posts: 69  ZCNE Certified
    First Comment Friend Collector Fifth Anniversary ZCNE Switch Level 1 Certification - 2020
    +1 !
    Best regards