Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Import wildcard certificate into Brightmail 8.0.2

Updated: 11 Aug 2010 | 9 comments
Terabyte Computers's picture
0 0 Votes
Login to vote

I found another post but it was over a year old so I'm looking to see if there's any new info.  We have a wildcard certificate, *.domain.com, issued by GoDaddy and would like to use it in Brightmail Gateway too.  Can this be done?

discussion Filed Under:

Comments

Marco Bicca's picture
02
Oct
2009
0 Votes 0
Login to vote

Hi there, As long as you make

Hi there,

As long as you make the request on SBG, send the CSR to the entity and get the certificate back yes, you should be able to use it just fine.

You cannot just import the certificate without having a request first.

Thanks,
Marco Bicca

Terabyte Computers's picture
25
Oct
2009
0 Votes 0
Login to vote

That's not how you import a

That's not how you import a wildcard cert from any vendor.  You can do this on any real web server including Apache but it looks as though Symantec didn't bother to do that for it's version of Apache

Sean Trowbridge's picture
09
Feb
2010
0 Votes 0
Login to vote

I was able to have the

I was able to have the SBG CSR signed by my provider (Digicert) and install it successfully. The problem I have is it is not being sent to the browser. I still get the self-signed one.

2-9-2010 11-01-06 AM.png2-9-2010 10-59-55 AM.png
2-9-2010 11-01-56 AM.png

AdnanH's picture
09
Feb
2010
0 Votes 0
Login to vote

Hi Sean, If you intend to use

Hi Sean,

If you intend to use this cert for Control Center access, have you configured Control Center to use it?

You can configure Control Center to use a cert using the "User interface HTTPS certificate: " setting under Control Center Validation section on Control Center Settings page (Administration > Control Center).  You can select the cert that you want to use for Control Center from the "User interface HTTPS certificate: " drop down list.  I think it is currently set to "Demo Certificate".

Regards,

Adnan

Sean Trowbridge's picture
09
Feb
2010
0 Votes 0
Login to vote

OK - that worked - after

OK - that worked - after I added in DigiCert's CA chain.

AdnanH's picture
09
Feb
2010
0 Votes 0
Login to vote

Thanks for the update. Just

Thanks for the update.

Just to get some clarification:  you had already configured the Control Center to use the new cert when you posted the question, right?   Sorry to ask this question, but from your original post it wasn't clear to me whether you had already completed the Control Center configuration step or not.

So you are saying that it's only after you added the DigiCert's CA chain that the problem was resolved?

Thanks

Adnan

Terabyte Computers's picture
10
Feb
2010
0 Votes 0
Login to vote

What type of web server did

What type of web server did you specify for the cert you were able to import?  I've tried IIS, Apache, and Tomcat but SBG keeps saying "No stored certificate request matches this certificate."  I was able to import GoDaddy's intermediate cert into the CA tab but not the actual cert to use.

Perhaps Symantec could spend the few $ it takes to purchase a wild card cert from GoDaddy or another vendor and then put up a FAQ on how to do this.  For what is paid for SBG every year surely Symantec can afford to do that.

AdnanH's picture
10
Feb
2010
0 Votes 0
Login to vote

Hi, Are you trying to import

Hi,

Are you trying to import the cert without a corresponding CSR in the SBG?  Currently, you can not import a cert if it was not issued based on a CSR generated on SBG.  Please take a look at the following KB article:

http://service1.symantec.com/SUPPORT/ent-gate.nsf/...

Regards,

Adnan

Terabyte Computers's picture
10
Feb
2010
0 Votes 0
Login to vote

Every other web server on the

Every other web server on the planet supports importing a cert when it hasn't generated the CSR.  This just show poor product design.