NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
ViperGeek
Dec 15, 2016Apprentice
Status:
Engineering Investigation
Enhancement Request: User-supplied SSL certificates for remote management
There is currently no way to install a proper PKI-chained SSL certificate from a third party like Comodo or StartCom SSL. With all current versions of the NETGEAR firmware, when enabling HTTPS access for remote management, my/all browsers get angry because the R7000 is using a self-signed certificate:
I have a free StartCom SSL cert all generated and ready to install. The problem is, there is no supported way to install this certificate, intermediate cert, and private key, with the R7000.
- Dave
47 Comments
- dejikoAspirant
Netgear always promoting their products have very high security and usually announce a lot of so called "Security Advisory" about their products, and also provide a firmware upgrade to fix the security issues. But currently, if you login to your Netgear router everytime, almost all of the internet browers saying it is insecure, with a big red label to telling you the connection has a risk for leaking your information. This issue already happened more than 4 years, is it Netgear discards their security standard and put their product with a risk forever?
As per Netgear response, you can choose to use a third party firmware to fixed the problem, but in another channel they say if you use a third party firmware it is very high risk as they cannot ensure the information safety.As a large company or enterprises, I cannot choose such kind of insecure product, this is a very well known issue and easy to fix by adding a let's encrypt feature or upload a certificate manually. As a home user, there have many alternative product in the market already provided a solution for that. So, why we still choose Netgear?
Is necessary Netgear permit to add a third part valid certificate with TLS 1.2 or 1.3 support, instead the invalid www.routerlogin.net, I have a RAX120, this expensive router have the same limitation, why?
Exist the root certificate for the validation of the actual?
- vaudricFledgling
It's a must all modern browsers now block access to invalid certs which leaves us without the possibility to access the remote management site.
+1 on https://letsencrypt.org/ support!
- ZetsumieFledgling
I was shocked to see the time stamp on this knowing that three years and two months later this still hasn't been implemented. I'm on the road 3/4ths of the year and can only manage my router remotely, but the SSL certificate has always given me problems... What use is installing the certificate when it's only for routerlogin.net!? I don't care about SSL when I'm logging in through LAN...
- BrendanMcCoyFledgling
I also really would love this.. I bought a .dev domain and being stuck with a bogus cert is miserable.
- schumakuGuru - Experienced User
Well, we're in the Home environment here, so these must be considered consumer devices. Let's Encrypt is a nice solution for this market, as most consumers don't have own domains anyway. The same - lack of a bind ot a customer owned certificate - on the other hand is one of the trust-stopper for that CA. Doing false (say hype) marketing for ACxxxx, AD7200, AX6000 or AX11000 - all numbers most peoplne never see - have priority to keep the market aehm Dollars rolling. With the ability to generate CSRs, to import certificates, there isn't much business to generate. Figure. With thid kind of delay politics, the EoL for many of these devices will come long before they change from their late 1990s router specs. Sad but true.
- RNASguyLuminary@tool Fledgling on 2018-07-06 08:22 PM wrote:really hard to believe that this doesn’t have miore votes AND it is only in an engineering investigation stage for 9 months. if you are going to offer remote management then don’t do it half way, especially when it involves security. the d7000 self signed certs are rejected more and more as FF and Chrome up the security levels with each release - sure i can use IE, but not when I’m on my mobile device trying to give needed access to family at home. Please do TLS properly and have upload of certificate store as feature or remove remote management as it is broken in its current form.I could not agree more. Also please do NOT bake in Lets Encrypt. It is not a reliable CA. Given the times we are in all remote access is broken without HTTPS and a real CA cert.And why on earth has this been sitting here since Dec 2016. Really... it takes years of dev to get this??
- Chance1775Novice
Are these boards even moderated by NetGear? This was originally posted on 2016-12-15 and nothing????