Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ability to setup separate certificates for DoH, DoT, DoQ #5837

Closed
3 tasks done
savely-krasovsky opened this issue May 21, 2023 · 3 comments
Closed
3 tasks done

Ability to setup separate certificates for DoH, DoT, DoQ #5837

savely-krasovsky opened this issue May 21, 2023 · 3 comments
Labels
duplicate Duplicate or merged issues.

Comments

@savely-krasovsky
Copy link

Prerequisites

  • I have checked the Wiki and Discussions and found no answer

  • I have searched other issues and found no duplicates

  • I want to request a feature or enhancement and not ask a question

Description

What problem are you trying to solve?

Currently I know only one CA which issues SSL certificates for IPs, it's ZeroSSL. But in their free tier they issue one cert for the exactly one IP/domain, so I can't issue single certificate for both DoH and DoT.

Proposed solution

Add ability to choose separate certificates for DoH, DoT and probably DoQ. AFAIK it will allow to use DDR.

Alternatives considered

Buy ZeroSSL 50$ per month tier and create cert with IP, domain and wildcard domain to complete fulfill our needs with one certificate.

Additional information

@fernvenue
Copy link
Contributor

But in their free tier they issue one cert for the exactly one IP/domain, so I can't issue single certificate for both DoH and DoT.

May I ask why you can't use single certificate for both DoH and Dot? They are just working on different ports.

@savely-krasovsky
Copy link
Author

savely-krasovsky commented May 22, 2023

May I ask why you can't use single certificate for both DoH and Dot? They are just working on different ports.

By certificate for IP I mean something like https://1.1.1.1 where Cloudflare issued a cert with SAN=IP:1.1.1.1

It allows to use DDR standard.

@ainar-g
Copy link
Contributor

ainar-g commented Jun 28, 2023

Merging into #741.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
duplicate Duplicate or merged issues.
Projects
None yet
Development

No branches or pull requests

4 participants
@ainar-g @savely-krasovsky @fernvenue and others