NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
ViperGeek
Dec 15, 2016Apprentice
Status:
Engineering Investigation
Enhancement Request: User-supplied SSL certificates for remote management
There is currently no way to install a proper PKI-chained SSL certificate from a third party like Comodo or StartCom SSL. With all current versions of the NETGEAR firmware, when enabling HTTPS access for remote management, my/all browsers get angry because the R7000 is using a self-signed certificate:
I have a free StartCom SSL cert all generated and ready to install. The problem is, there is no supported way to install this certificate, intermediate cert, and private key, with the R7000.
- Dave
47 Comments
- GearEngineerNoviceValid Certificates are the foundation of security.
- shamarinVirtuoso
Did it https://community.netgear.com/t5/Idea-Exchange-For-Home/Implement-Let-s-encrypt-to-Nighthawk-serious/idi-p/1666096#M1906 You can vote for this.
- cmweissAspirantI don't care how https is enabled. I don't care if it's with a CA cert or with a self signed cert. I want https period.
- schumakuGuru - Experienced User
The feature request up here is NOT about Let's Encrypt. It's about generic CA support.
I'm fine if you want Let's Encrypt. Use search or file a dedicated feature request if there isn't one for it. - schumakuGuru - Experienced User
Do you understand what makes a certificate "trusted"?
What makes a browser show an all green or a limited green "trust"?
Let's Encrypt does open to many doors for abuse. The registration and the related processes are not good enough for a trust. "But my browser showed a green blah....".
Do you understand what is required to have major OS and browsers trusting a CA? Up front: A lot of money.
- shamarinVirtuoso
This router is for home users (SOHO router) and that's why we need such feature in it (implement Let's encrypt CA). Let's encrypt sert will be much more usable and secure then self signed untrusted sert generated by R7000.
- schumakuGuru - Experienced User
Exactly, that's why we remove Let's Encrypt CA from the systems again. The proceses are not sufficient, and don't compare in any aspect to any other real CA. If you don't understand this part - keep having fun with it, it's ok for home users. It's not good enough for security and trust.
- shamarinVirtuoso
Self signed sert is allready implemented in R7000 and it's not secure because all browers show that it's untrusted and that's why you couldn't connect via HTTPS.
- shamarinVirtuoso
By this year they got official authority by all browsers and operating systems. So Let's encrypt is good and that's why now all other router manufactures using Let's encrypt. Also Let's encrypt has a very good and easy sert generating software ACME.
- cmweissAspirantI would love that and I support that. But even basic self signed certificate support would be improve security for those who know how to manage self signed certs.