Answer the question
In order to leave comments, you need to log in
Multi-domain SSL certificate for more than 100 domains?
Colleagues, there is a project that provides the option to bind your domain.
In fact, all requests are made to one php script, but depending on the domain, other content is opened.
And the question arose about SSL certificates that have a limit on 100 different domains.
How it is possible to bypass it? Other than how to keep multiple installs?
Somehow this is done on large projects.
The main thing is that there are no redirects and everything is processed by one script.
Answer the question
In order to leave comments, you need to log in
On large projects, as many certificates as needed are simply made.
If we talk about the network within the corporation, it simply creates its own CA and the root certificate is distributed by politicians to all machines, and issue at least a million certificates there.
In general, the restriction consists of two parts - the issuer restriction, look for another CA where there is no such restriction. For example Comodo - the limit is 2000.
Secondly, not all browsers are ready to load multi-kilobyte certificates. If you end up with a certificate that is larger than 16 KB or 64 KB, various levels of problems may arise.
Somehow this is done on large projects.
What is the problem with issuing an individual certificate to clients via letsencrypt?
Indeed, in order to bind your domain to your service, the client will have to specify the ip of your servers in the A-records of the domain, which means that you can issue a certificate for each domain without any problems.
So, for example, it makes github pages where anyone can tie up their domain, and github takes over the release and renewal of the ssl certificate.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question