Jump to content
[MUST READ] Forum Rules ×

Discussion about ssl generator.


Mayank657

Recommended Posts

12 hours ago, SpookyKipper said:

It's so easy, just add a txt record to the pichisdns.com domain and every domain that cname to it will have the dame txt records

Bro I am making an ssl Generator to issue certs like let's Encrypt. But after verification it gives me a txt value and in my knowledge txt records doesn't work in free I was asking @BastelPichi that he had also make an ssl Generator and it give cname record I was asking how can I do that.

Link to comment
Share on other sites

7 hours ago, Mayank657 said:

Bro I am making an ssl Generator to issue certs like let's Encrypt. But after verification it gives me a txt value and in my knowledge txt records doesn't work in free I was asking @BastelPichi that he had also make an ssl Generator and it give cname record I was asking how can I do that.

Spooky Kipper already answered you.

You can read more about it here: https://letsencrypt.org/docs/challenge-types/#dns-01-challenge

Link to comment
Share on other sites

19 minutes ago, Mayank657 said:

If I am saying wrong.

So, didn't understand what are saying please explain it more briefly.

Ok, so

 

1. You sent a request to Let's Encrypt for certification

2. Let's Encrypt gives you a txt record to add

3. You add the record to a dummy domain (e.g. XXX.acmeverify.example.com)

4. Your users CNAME to XXX.acmeverify.example.com

5. The TXT will get added to user's domain automatically (because they CNAME'd)

6. Validation passed & certificate issued

Edited by SpookyKipper
Link to comment
Share on other sites

3 hours ago, SpookyKipper said:

Ok, so

 

1. You sent a request to Let's Encrypt for certification

2. Let's Encrypt gives you a txt record to add

3. You add the record to a dummy domain (e.g. XXX.acmeverify.example.com)

4. Your users CNAME to XXX.acmeverify.example.com

5. The TXT will get added to user's domain automatically (because they CNAME'd)

6. Validation passed & certificate issued

So, you are saying that if the txt is example so the cname will be example.acmeverify.example.com

If it not like this can you please explain me more briefly. It will be very helpful 

Link to comment
Share on other sites

10 minutes ago, Mayank657 said:

If it not like this can you please explain me more briefly

You know how to add a txt record I suppose?

 

Let's say the TXT is "abc123", it can be put to "abc123.example.com",  "xyz789.example.org", basically any domain.

 

It is fully your choice where to put it, and just tell your user to cname to that domain where you have added the txt record on

Edited by SpookyKipper
Link to comment
Share on other sites

2 hours ago, SpookyKipper said:

You know how to add a txt record I suppose?

 

Let's say the TXT is "abc123", it can be put to "abc123.example.com",  "xyz789.example.org", basically any domain.

 

It is fully your choice where to put it, and just tell your user to cname to that domain where you have added the txt record on

Ok ok

Link to comment
Share on other sites

1 hour ago, Anyx said:

They do? I tried ordering a *.domain.com certificate and the tool didn't accept it.

Yes they do the tool will automatically generate a wildcard ssl if look in subject alternative name there will be domain.com and *.domain.com you can also see the byet.net ssl they also have a wildcard ssl

Link to comment
Share on other sites

21 hours ago, Anyx said:

They do? I tried ordering a *.domain.com certificate and the tool didn't accept it.

Spookhost use wildcards on Google Trust and Let's Encrypt too. (You enter the non-wildcard domain and the wildcard variant will be automatically added)

 

The subject(not alternative names) of the certificate is the non-wildcard one, so vPanel accepts it.

 

It is done because if you add both the root and www variant of the domain, two cname records need to be added (@ and www). However, with wildcard records, only 1 cname record is needed (where the cname contains two txt records)

 

This is not required with GoGetSSL because they automatically adds the www subdomain 

Edited by SpookyKipper
Link to comment
Share on other sites

2 hours ago, SpookyKipper said:

Spookhost use wildcards on Google Trust and Let's Encrypt too. (You enter the non-wildcard domain and the wildcard variant will be automatically added)

 

The subject(not alternative names) of the certificate is the non-wildcard one, so vPanel accepts it.

 

It is done because if you add both the root and www variant of the domain, two cname records need to be added (@ and www). However, with wildcard records, only 1 cname record is needed (where the cname contains two txt records)

 

This is not required with GoGetSSL because they automatically adds the www subdomain 

I never actually realized this, InfinityFree's tool said "the www subdomain is automatically included" and I never checked the actual certificate to see that they issue a wildcard. Nice, and I can understand why it isn't mentioned (people would be confused thinking they can actually use it as a wildcard which vPanel doesn't allow).

Well, it seems that you also got your answer @Mayank657:

2 hours ago, SpookyKipper said:

with wildcard records, only 1 cname record is needed (where the cname contains two txt records)

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...