Lets Encrypt - Public Domain on FAC for Guest Portal
I have a query about a FAC for a customer, it acts as a Captive Portal for Guest WIFI, and it works fine except for Apple Devices, there is an issue with GoDaddy and trust on IOS, which neither of the vendors seem to care about, so I need to move from GoDaddy,
The reason I am using it is so that Guests don't get a secure warning when accessing the FAC portal page, The company has a domain, that I created a cert for and used DNS to point that FQDN internally to the FAC, this to me is very clumpy, but that's the way its done!
The customer doesn't want to use the existing domain and will purchase a new one, "companyxyz.com" for example. How would this work? the FAC is on an internal IP, and if I create a CSR for "fac.companyxyz.com" and get it signed by lets encrypt. How will this resolve to an internal IP? would the DNS for the domain allow a Private IP?
Has anyone ever done Lets Encrypt on a FAC? Ill be using this same domain to create certificates on the FortiGate's for the Wireless re-direct, so "gate1.companyxyz.com" and "gate2...." etc these also need to point to the Wireless interfaces which are private IPs
Any pointers, or advice greatly appreciated.
