Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dunkelmorten
Contributor
Contributor

Public SSL Certificate Domain Validation options

Hello all,

 

a customer of mine is running Remote Access using MEP VPN with site configuration having gateways defined by ip addressed insteaf of FQDNs using MFA with a third party provider solution hosted internally. As of now the GW certificates are self-signed by CP ICA and have been added to customer devices trust stores.

We are currently planning to switch to SAML/IdP integration using public certificates. Initially, in order not to change too many things at once, we don't want to change site configuration, but only do the SAML/IdP stuff and the public certificates. By this, the CSRs for the public certificates have been created as SAN with VIP FQDN, Node FQDN and their ip addresses as well.

However, public PKI provider (GlobalSign) requires domain validation (as per security defaults) which is working for the FQDNs within the CSR but not for the ip addresses. These would need to be checked by looking up a file on the CP web server under the path https://%GW-IP%/.well-known/pki-validation/gsdv.txt

Does anybody know if there is an option to create this file and knows in which path this needs to be located at enabling for domain validation of ip addresses provided in a SAN certificate?

I was trying with no luck to create at "/opt/CPshrd-R81.20/conf/multiportal/httpd-conf/" where "UserCheck" and "saml-vpn" folders are found with sub-folders ".well-known/pki-validation" and adding the required text file "gsdv.txt". Additionally, changed folder and file permission to 644, but the file could not be looked up externally, neither when addressing it my browser.

 

BR,

Morten

0 Kudos
0 Replies

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events