Feature request: Let's Encrypt option for Certificates in USG Flex H series

Options
JoostGroot
JoostGroot Posts: 13 image  Freshman Member
First Comment Fourth Anniversary

We can use certifiactes (self-signed and CA-signed) the USG flex H series, but since the expiration periods are shortening, we would like to user a auto-renew certificate. But there is no option in the firewalls.

The vpn 2FA page is still also not working with the installed certificate, so that would be a prefect time to fix both that issue and add the feature for setting up a Let's encrypt or other auto-renew setup.

Firewalls are maintained within Nebula, but we still need to access the local firewall portal at times. It is not realy safe practice to accept invalid certificates, so we realy want to user our own host and domain for access and a valid certificate.

Hope this feature can be build in.

Tagged:
2 votes

Active · Last Updated

Comments

  • PeterUK
    PeterUK Posts: 4,656 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    Options

    Really I was hoping for push back for the shortening of certificates

    I'm hoping that the move to ionos will soon do ACME soon and that Zyxel will add support for this Let's encrypt that I have setup for my DNS-over-HTTPS is setup and uses port 80 to verify.

    But I would like ACME by Email where like FLEX renews the challenge is sent by Email then FLEX connects to my Email server by POP port 110 to do challenge and certificates installed

  • Zyxel_Tina
    Zyxel_Tina Posts: 960 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments
    Options

    Hi @JoostGroot,

    Good news! The upcoming firmware v1.39 (planned release around July 27) will add support for Let's Encrypt certificates, including automatic renewal. This should resolve the manual certificate management issue you raised for the local device portal.

    Zyxel Tina

  • Zyxel_Tina
    Zyxel_Tina Posts: 960 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments
    Options

    Hi @PeterUK,

    Regarding your request, Let's Encrypt's standard ACME validation mechanisms are strictly limited to HTTP-01, DNS-01, and TLS-ALPN-01. Because Let's Encrypt does not support domain verification via email or mail protocols, this requirement cannot be accommodated due to the certificate authority's built-in design specifications.  

    We appreciate your understanding.

    Zyxel Tina

  • PeterUK
    PeterUK Posts: 4,656 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited August 17
    Options

    Hmm interesting email support will not be added as a way for ACME.