View previous topic :: View next topic |
Author |
Message |
medzoom
Joined: 27 Dec 2011 Posts: 45 Location: Austria
|
Posted: Fri Feb 02, 2018 9:19 am Post subject: login-Page on https / ssl-certificate |
|
|
does anyone has already made the login-page on https?
Some clients do have problems to overrule one firefox the "insecure warning" while making the login?
On privious posts I already read that I do have to aquire a ssl-certificate on my private-ip . But how do I setup the ssl
best regards |
|
Back to top |
|
|
alan Forum facilitator
Joined: 26 Sep 2003 Posts: 4435
|
Posted: Fri Feb 02, 2018 3:45 pm Post subject: |
|
|
Please check out chapter 5 of firstspot_guide.pdf. Note that you need to use domain name Login Page URL if you want enable SSL in the login page. _________________ ~ Patronsoft Limited ~ |
|
Back to top |
|
|
medzoom
Joined: 27 Dec 2011 Posts: 45 Location: Austria
|
Posted: Fri Feb 02, 2018 4:26 pm Post subject: |
|
|
Dear Alan,
sorry I didnt look into the manual myself.
Yes it is perfectly discribed there.
thank you - I will try it |
|
Back to top |
|
|
medzoom
Joined: 27 Dec 2011 Posts: 45 Location: Austria
|
Posted: Fri Feb 02, 2018 4:36 pm Post subject: |
|
|
I do have a question to the certificate...
when I buy an ssl-certificate, do I need a Wildcard-SSL certificate?
as far as I see, the following sites are visual to the Customer-site
> logout.firstpot.org (or logout.my.domain)
> login.firstspot.org
As I read on goDaddy.com, I would need an <Wildcard-SSL> for <firstspot.org> (or the corresponding for me like *.my.domain), so that certificate will include the Subdomains logout.firstpot.org and login.firstspot.org?
best regards |
|
Back to top |
|
|
alan Forum facilitator
Joined: 26 Sep 2003 Posts: 4435
|
Posted: Fri Feb 02, 2018 5:03 pm Post subject: |
|
|
No. Currently, you can only SSL-enabled the login page. _________________ ~ Patronsoft Limited ~ |
|
Back to top |
|
|
medzoom
Joined: 27 Dec 2011 Posts: 45 Location: Austria
|
Posted: Tue Feb 20, 2018 6:54 am Post subject: |
|
|
I tried to configure the "show IP address or domain name firstpot.org.." and used an own domain myself (which I own but doent have activated on an DNS-Server) and now after starting it says, that the DNS-Server can not find that Domain / URL. "what acctually is correct!"
As I use the Firstspot on an internal network, I will never register an Domain to the internal network address?
What is the solution therefore? I use 10.20.7.2 for the "visitor-network" so, this IP I will never activate on an official DNS-Server?
Do I therefore need my own DNSServer on my Firstspot-Server to set my domain to my private ip-address? |
|
Back to top |
|
|
alan Forum facilitator
Joined: 26 Sep 2003 Posts: 4435
|
Posted: Tue Feb 20, 2018 7:04 am Post subject: |
|
|
Did you add your domain in Exception Free Websites manually? This is not required. _________________ ~ Patronsoft Limited ~ |
|
Back to top |
|
|
medzoom
Joined: 27 Dec 2011 Posts: 45 Location: Austria
|
Posted: Tue Feb 20, 2018 7:09 am Post subject: |
|
|
no I havent added any domain-name in the "free domain names"
but I have both DNS-Ips (of my internet-provider) in the "free IP addresses" added (I did this many year??) |
|
Back to top |
|
|
medzoom
Joined: 27 Dec 2011 Posts: 45 Location: Austria
|
Posted: Tue Feb 20, 2018 7:10 am Post subject: |
|
|
this is the error-message
Code: |
Tue Feb 20 07:31:09 2018 ***** All the error messages of session started at Tue Feb 20 07:31:09 2018 are shown below *****
Tue Feb 20 07:31:09 2018 Cannot use external DNS server with domain name based login page URL. Either you change DHCP -> Preferred DNS server IP and Alternate DNS server IP to 0.0.0.0, or you set Authentication Server -> Show IP or domain name in login page URL to IP instead
|
|
|
Back to top |
|
|
alan Forum facilitator
Joined: 26 Sep 2003 Posts: 4435
|
Posted: Tue Feb 20, 2018 7:13 am Post subject: |
|
|
You cannot use your DNS in this case since FirstSpot needs to resolve your domain correctly in the visitor side.
Please remove your Exception Free Websites DNS IP, and set the FirstSpot DHCP -> Preferred DNS server IP and Alternate DNS server IP to 0.0.0.0, and then restart FirstSpot. _________________ ~ Patronsoft Limited ~ |
|
Back to top |
|
|
medzoom
Joined: 27 Dec 2011 Posts: 45 Location: Austria
|
Posted: Tue Feb 20, 2018 8:37 am Post subject: |
|
|
mercy.. it worked perfect!
I will now try to get an official SSL-certificate for my new "internal" domain |
|
Back to top |
|
|
medzoom
Joined: 27 Dec 2011 Posts: 45 Location: Austria
|
Posted: Tue Feb 20, 2018 9:20 am Post subject: |
|
|
Dear Alan,
to the "special"-domain, what happens when the domain is indeed registered to an official DNS-Server over the internet and therefore is theoretically linked to an real website?
would the firstspot-server overrule the request for that domain for the clients on the visitor-net to the "real" website and forward it to the local address of the firstspot itselft?
I do have problems register the SSL for my domain, as this domain doesnt have an official DNS-entry and can not register that domain on godaddy.com
|
|
Back to top |
|
|
alan Forum facilitator
Joined: 26 Sep 2003 Posts: 4435
|
Posted: Tue Feb 20, 2018 9:25 am Post subject: |
|
|
There will be no problems. Our DNS server will override the official entry (e.g. the default login domain name URL firstspot.org is registered by us) _________________ ~ Patronsoft Limited ~ |
|
Back to top |
|
|
medzoom
Joined: 27 Dec 2011 Posts: 45 Location: Austria
|
Posted: Tue Feb 20, 2018 10:07 pm Post subject: |
|
|
dear Alan,
I did all the my-server.* stuff according to the manual, but my clients doesnt get an correct certificate.
I do have have finally registered an certificate on my own domain, did all the authorisation with the certificate-station, but finally I get only an SHA-2 certs by godaddy? May this be the problem?
Which logfile shell I use to get more details? |
|
Back to top |
|
|
alan Forum facilitator
Joined: 26 Sep 2003 Posts: 4435
|
Posted: Wed Feb 21, 2018 2:23 am Post subject: |
|
|
Please post the client error screenshot here _________________ ~ Patronsoft Limited ~ |
|
Back to top |
|
|
|