Cert SSL - autorenew via DigiCert or Sectigo or others

Options

Hello everyone,

I recently purchased an SSL certificate, but I read about the 200-day renewal hassle that will later become 100 and then 47 days. It's a terrifying thing for manual certificate replacement, which requires the H-series firewall.How can someone get a recognized SSL certificate (on a domain of the customer's choice like *.example.com) that auto-renews automatically, certifying the customer's firewall, without losing their patience over replacing it manually?

I know that recent uOS firmware updates should have Let's Encrypt / ACME support. However, since a wildcard certificate (*.domain.com) strictly requires the DNS-01 challenge (validation via DNS TXT records), how can we properly configure the USG FLEX H to talk with external DNS providers (like Cloudflare or GoDaddy) to fully automate this without human intervention?

Thanks!

All Replies

  • PeterUK
    PeterUK image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited August 12
    Options

    Its currently only supports Let's Encrypt and even that has problems as in the way it does the challenge which I would liked changed.

    I know I'm going to hate this 47 days on some of my kit that has to be done manually

    I have not looked into DNS challenge as to how that works but guess that be useful for those without inbound traffic support.

  • GiuseppeR
    GiuseppeR image  Guru Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Engineer Level 1 - Nebula 500 Comments 5 Answers
    Options

    It is a nonsense to have to replace MANUALLY a cert that you can buy and install on your domain, your own domain, every 47 days

    Let’s Encrypt is not my solution, a wildcard with rock solid background it is

  • PeterUK
    PeterUK image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    Options

    Guess you can put it in ideas

    My guess is Zyxel just thought the UI to be SSL does it matter what cert it used as long as it valid and seeing as Let’s Encrypt is free do we need to support other types?

  • GiuseppeR
    GiuseppeR image  Guru Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Engineer Level 1 - Nebula 500 Comments 5 Answers
    Options

    I found this one:

    The problem is to have a cert that is NOT autosigned by Zyxel but it is recognized as greed when browsing, a wildcard could do that

  • GiuseppeR
    GiuseppeR image  Guru Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Engineer Level 1 - Nebula 500 Comments 5 Answers
    edited August 12
    Options

    Hi @Zyxel_Melen

    I have some doubts about cert SSL applied to FWs.

    These are my questions:

    1. What is the exact CLI command syntax for importing a third-party PKCS#12 (.pfx/.p12) certificate on the USG FLEX H series (uOS), including any specific requirements for how the PKCS#12 file must be built (encryption method, cipher, password format) to be accepted?

    2. Is there a documented REST API endpoint for uploading/importing certificates on USG FLEX / ATP (ZLD) or USG FLEX H (uOS) devices — for automation purposes, outside of the web GUI?

    3. Does Nebula Smart Sync support pushing a certificate centrally to managed USG FLEX H-series devices via the Nebula Control Center, and if so, is there an API endpoint for this that could be called programmatically?

    4. Is there a public roadmap or planned feature for native ACME protocol support (automatic Let’s Encrypt / third-party CA renewal) on USG FLEX, ATP, or USG FLEX H series firmware?

  • Zyxel_Tina
    Zyxel_Tina image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments
    Options

    Hi @GiuseppeR,

    Thank you for your input. I have forwarded your request to the relevant team for review.

    Our team would like to discuss the matter with you in more detail. Please check your private messages.

    Zyxel Tina