NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
ViperGeek
Dec 15, 2016Apprentice
Status:
Engineering Investigation
Enhancement Request: User-supplied SSL certificates for remote management
There is currently no way to install a proper PKI-chained SSL certificate from a third party like Comodo or StartCom SSL. With all current versions of the NETGEAR firmware, when enabling HTTPS access for remote management, my/all browsers get angry because the R7000 is using a self-signed certificate:
I have a free StartCom SSL cert all generated and ready to install. The problem is, there is no supported way to install this certificate, intermediate cert, and private key, with the R7000.
- Dave
47 Comments
- schumakuGuru - Experienced User
The original request was done to have the ability to generate standards compliant CSR (Certificate Signatue Requests) and have these signed by a CA.
Lets Encrypt is a different beast - there we need the access for a specific Registration Authority. And seriously, as the security officer of a security oriented business I would not trust the Lets Encrypt CA because of the lack of trust of the registration process - it's a CA trust strip from our systems. But yes, for the average user it's OK.
- shamarinVirtuoso
I know how to setup self signed sert to exception in browser, but it's not very usable for manys. We just need an implementaion of Let's encrypt sert in R7000 and also HTTPS for GUI access in a security reasons.
- cmweissAspirantBecause you don't know how to do it doesn't mean that others don't.
- shamarinVirtuoso
You are wrong, now the router make self signed sert, but all browsers denied it as self signed and untrusted. With Let's encrypt no action needed from the user, only to check in router GUI to use HTTPS or FTPS. All other things like generating sert and it's prolongation is done by router FW in automatic way.That's why we make such pettition.
- cmweissAspirantIf you create the cert then you trust the cert. If you trust the cert then so will your browser. It should be an option for those who know how to use it.
- shamarinVirtuoso
But self signed sert will be denied by most of the browsers, that's why most of the manufactures now use Let's encrypt sert for this purpose, Asus use it, Zyxel Keenetic, D-Link. So free Let's encrypt sert would be very fine for FTPS, HTTPS for GUI and remote access.
- cmweissAspirantEven a self signed cert would be acceptable for home use.
- EffinayNovice
+1
- vortex13Novice
I also need this, I am unable to connect from work because the block sites without a cert.
- swailsFledgling
I would also like this.