Avatar of ksfrist
ksfristFlag for United States of America

asked on 

Question Regarding multi Standard SSL Certs verses Wildcard Cert - Microsoft AD CA related.

I"ll apologize up front for any ignorance on this topic, as I've been scouring Microsoft KB articles and trying to understand better.
 
Through GoDaddy, our Org has purchased 2 standard SSL Certificates for our multi ISP VPN connections and one wildcard SSL Certificate for a specific application server located internally to our domain but public facing.
 
We also need to pick up an SSL Cert for use for Radius authentication for our wireless, and I'm trying to determine if I just need to purchase yet another standard SSL Certificate or another Wildcard Certificate and try to consolidate everything to get it on the same renewal cycle.
 
We use an internal Microsoft AD CA for our current Radius authentication with a self signed Cert, so my assumption would be if I consolidated under a blanket Wildcard Cert it would need to be housed there.

We're going to a GoDaddy Cert for Radius authentication because of the Android 11 update.
 
We also have the question of other internal resources that use an https connection and how to secure those. Nothing public facing, all internal DNS, such as ds01.tigers.org or vc01.tigers.org that point to our datastores and vCenter. Would I need to add those DNS entries to the original CSR for the wildcard cert?

I'm pretty sure we'll stick with GoDaddy as that's what the purchasing/director is comfortable with, although other recommendations are welcome.
 
I hope this question makes sense or it may be 2 different questions. I so appreciate any guidance or a smack over the head.
Microsoft* active directory certificate serviceSSL / HTTPS* 802.1x

Avatar of undefined
Last Comment
ksfrist
Avatar of kevinhsieh
kevinhsieh
Flag of United States of America image

A wildcard cert works for all hosts on the domain. You don't need to specify them in advance in the CSR. There are some services that do not work with wildcard certs. They include Exchange and AD LDAPS. You should be able to use your existing wildcard cert with NPS for your wireless authentication.
Avatar of ksfrist
ksfrist
Flag of United States of America image

ASKER

Thanks for the quick response. Our existing wildcard cert is installed on a Linux install for our MDM application. We had to purchase it for that specific instance and as my other Sys Admin states, "let's pretend that doesn't exist".

If I'm understanding you correctly, if I purchase a Wildcard cert and install it on our AD CA Server it would encompass all the internal hosts and Radius authentication?

I appreciate it.
ASKER CERTIFIED SOLUTION
Avatar of kevinhsieh
kevinhsieh
Flag of United States of America image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
Avatar of ksfrist
ksfrist
Flag of United States of America image

ASKER

Understood. Our CA and NPS Servers are the same VM. I should have mentioned that part.. Thanks so much.
Avatar of kevinhsieh
kevinhsieh
Flag of United States of America image

CA should NOT be on a DC. NPS works well on DC, but can be separate.
Avatar of ksfrist
ksfrist
Flag of United States of America image

ASKER

It's certainly been a part of the confusion. Thanks so much for the recommendation.
SSL / HTTPS
SSL / HTTPS

HTTPS is a protocol for secure communication over a computer network which is widely used on the Internet. HTTPS consists of communication over Hypertext Transfer Protocol (HTTP) within a connection encrypted by Transport Layer Security (TLS) or its predecessor, Secure Sockets Layer (SSL). The main motivation for HTTPS is authentication of the visited website and to protect the privacy and integrity of the exchanged data. HTTPS is widely used for protecting page authenticity on all types of websites, securing accounts and keeping user communications, identity and web browsing private.

9K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo