Skip to main content
AlftechCZ
New Member
April 21, 2022
Question

LetsEncrypt multi-SAN certificate (multi-Subject Alternative Names)

  • April 21, 2022
  • 6 replies
  • 13033 views

Hello,

 

How to solve multi-Subject Alternative Names in LetsEncrypt Certificate in FortiWeb. There are no way to insert in letsencrypt certificate more than one DNS name.

We have website with 15+ dns alternative names.

 

Thank You for your reply.

6 replies

jintrah_FTNT
Staff
Staff
April 21, 2022

Hi,

 

Do you mean that the certificate cannot contain 15+ alternative names? If so this should be checked with some other root CA other than letsEncrypt and not on FortiWeb, if they can provide such certificate with many alternate names.

But if you already have required certificate with multiple SAN, we could check on adding required domains to FortiWeb.

 

Best regards,

Jin

AlftechCZ
AlftechCZAuthor
New Member
April 21, 2022

Hello, 

 

My question is where to set alternate names when I create LetsEncrypt certificate in FortiWeb Gui. 

There is just One DNS name in create dialog. 

 

best Regards

Ales

jintrah_FTNT
Staff
Staff
April 21, 2022

Hi Ales,

 

Are you referring to generating a CSR?

 

Best regards,

Jin

AlftechCZ
AlftechCZAuthor
New Member
April 21, 2022

How to set multidomains in Creation Dialog - see picture bellow.

Certbot, WinAcme and all other bots can request multi-Subject Alternative Names LetsEncrypt certificates.

FortiWeb can't do this?

 

AlftechCZ_0-1650528224358.png

Certificate that have alternate names like this

AlftechCZ_0-1650529985781.png

 

 

jintrah_FTNT
Staff
Staff
April 21, 2022

Hi,

 

Thanks for the attachment, I believe you could enter different domains separated by comma.

 

Best regards,

Jin

AlftechCZ
AlftechCZAuthor
New Member
April 21, 2022

Hi,

 

BTW is this noted somewhere in documentation for FortiWeb?

 

best regards,

Ales

 

jintrah_FTNT
Staff
Staff
April 21, 2022

Hi,

 

I do not know if there is a doc  that could note all custom requirements and possibilities.

 

best regards,

Jin

 

 

AlftechCZ
AlftechCZAuthor
New Member
April 21, 2022

Hi,

 

coma separated and semicoma separated DNS names are not supported !

 

Let's Encrypt failed to issue certificate due to error. type: urn:ietf:params:acme:error:rejectedIdentifier, detail: Error creating new order :: Cannot issue for Domain name contains an invalid character

jintrah_FTNT
Staff
Staff
April 21, 2022

Hi,

 

It appears that SAN is not a supported option then. You may want to add one letsencrypt certificate for each domain and later add these certificates as SNI certificate members. I would suggest to open a FortiCare ticket to confirm and gain needed assistance.

 

Best regards,

Jin

AlftechCZ
AlftechCZAuthor
New Member
April 21, 2022

Wow that means 20webs per 10 Alternated DNS names = 200 Certificates + 200 SNI records..... I thing certificate issuing has some limits for one IP address issuer.

 

May be big trouble not just for us.

Please can be ticket to solving this situation inserted in high priority?

Resolution is simple - inserting DNS + alternate DNS names in separated input field and properly issuing on LetsEncrypt servers. As is known on other certificates bots i say (certbot, winacme)

 

Thank You

Ales

jintrah_FTNT
Staff
Staff
April 21, 2022

Hi,

 

This would be a feature request.

 

Best regards,

Jin

petep-cts
Visitor III
December 13, 2023

I'm encountering a comparable issue. My intention is to utilize the built-in Let's Encrypt option for FortiClient VPN users. Given that we have two ISPs, the SSL VPN is configured to listen on both interfaces. I've established two DNS A Records, but it seems that I can only use a single domain when using the cert creation wizard. Consequently, the backup IP won't have a valid certificate. Any recommendations or suggestions?