Devices & Servers · SSL certificates

Replace the self-signed certificate on every box you log into

Firewalls, phone systems, mail servers, NAS boxes, hypervisors, switch consoles — almost every one ships with a self-signed certificate and warns on first login. It stays that way for years, until nobody reads warnings at all.

  • The habit is the real costA rack that warns on every login teaches a team that certificate errors are normal. That is exactly the habit someone attacking you is relying on, and it does not stay in the rack.
  • Cheaper than one hour of the outage it preventsFrom $14.99 a year for a hostname, or one wildcard across a whole estate. Set against a mail outage or a failed audit it is not a close call.
  • Nothing has to face the internetDNS validation issues a publicly trusted certificate for a host that is only reachable inside your network. Management interfaces stay exactly as private as they are today.
  • It installs on anything that takes a keyIf the appliance has a certificate upload field, it takes one of these — and if it fights you, installation support is included.
  • $14.99a year for a single hostname
  • 69% offits list price of $49
  • DNS validatednothing has to be exposed
  • Any appliancefirewall, PBX, NAS, hypervisor, mail

Start with the hardware you own

This is the shortest way through. Each page is built around the equipment itself — the appliances it covers, the hostnames they present, and the certificate that fits, with prices you can act on rather than enquire about.

Already know your hostname list?

Then skip the hardware pages. Every estate is one of these four shapes, and the only two questions that decide it are how many hostnames you need on the certificate and whether your company name has to appear inside it.

One device, one hostname

vpn.acme.com

A single firewall, one NAS, one PBX, one server — answering on one public name. Nothing more elaborate is needed, and it is live in minutes.

What that means here Comodo PositiveSSL Certificate
  • Domain validated · issued in minutes
  • $10,000 warranty
from $14.99 $49 per year, before term discounts
Details

Several devices, one domain

vpn. · pbx. · nas. · ilo01. — all under acme.com

Past three appliances this is almost always the cheapest route, and it covers every hostname you add later without a reissue. The same file goes on every box.

What that means here Comodo PositiveSSL Wildcard Certificate
  • Domain validated · issued in minutes
  • Covers unlimited subdomains of the domain
  • $10,000 warranty
from $121.98 $162.64 per year, before term discounts
Details

Devices across several domains

acme.com + acme.co.uk + secondbrand.com

A wildcard only stretches across one domain. When the estate spans two or three registered domains, each name is listed explicitly instead — and you get one renewal date rather than five.

What that means here Comodo PositiveSSL Multi-Domain Certificate
  • Domain validated · issued in minutes
  • 3 hostnames included, up to 247 in total
  • $10,000 warranty
from $114 $165 per year, before term discounts
Details

Your company name has to be in it

ISO audits, PCI scope, client security questionnaires

Organisation validation vets your registered company and writes it into the certificate where an auditor can read it. The encryption is identical — the vetting is what you are buying.

What that means here Comodo InstantSSL Pro SSL Certificate
  • Organisation validated · issued in 1-3 days
  • $100,000 warranty
from $66.93 $89.24 per year, before term discounts
Details

What the self-signed certificate is actually costing you

Not an abstraction. These are the four things that go wrong, in the order people usually notice them.

  • Your team learns to click through warnings Once staff accept a warning on the firewall every morning, they accept the one on a phishing page too. This is the expensive one, and it is invisible until it is not.
  • Things stop working, quietly Mail clients drop connections, VPN clients refuse to launch, mobile apps fail to sync, API integrations time out. None of it says “certificate” in the error, so it gets debugged as something else for a day first.
  • It comes up in every audit and questionnaire Self-signed certificates on management interfaces are a standing finding in ISO 27001 and PCI reviews, and a standard question on customer security questionnaires.
  • You cannot tell a real problem from the usual noise When a device warns permanently, a genuine interception or an expired chain looks exactly like Tuesday. A clean estate makes the one real warning visible.

Two things to check before you order

No public authority can issue for an internal-only name

Names like pbx.local, fw01, nas.internal or a bare IP address such as 192.168.1.1 cannot be covered by any certificate on this site — the industry stopped issuing for them on 1 November 2015, and no supplier can work around it. Give the device a real, registered DNS name first, for example pbx.yourcompany.com, even if it only ever answers on the internal network. Split-horizon DNS resolves it to the private address inside and to nothing at all outside, and validation is done over a DNS record so nothing has to be exposed.

Check the server count before you check out

Everything recommended on this page can go on as many boxes as you like. Some of the enterprise ranges elsewhere on the site are licensed for a set number of servers, with extra licences sold as an option at checkout, and the count is shown on each product page. If you are covering five firewalls with one of those, read it first — this is the single most common reason somebody buys the wrong thing.

What comes with the price

  • Lowest price guaranteeFind the same certificate cheaper anywhere and we match it.
  • 10-day money backOn SSL certificates: cancel inside 10 days for a full refund. Read the policy.
  • Free unlimited reissuesSwap a device or change a hostname mid-term at no cost.
  • Free installation supportStuck on an appliance? Our engineers finish the install with you.
  • Real engineers, 24×7Not a script. People who install these for a living.
  • Free tools, no sign-upCSR generator, checker, decoder and four more.

How the install actually goes

Three steps on almost every appliance, and the same three whether it is a FortiGate or a Synology.

  1. Generate the request on the device Nearly every appliance will create the signing request itself and keep the private key on the box, which is safer than moving a key around. Where one cannot, our free CSR generator makes the request and gives you the matching key.
  2. Order and validate Paste the request in at checkout. Domain validation is an email or a DNS record and takes minutes; organisation validation adds a company check of one to three working days.
  3. Upload the certificate and its chain This is where appliance installs go wrong. Browsers forgive a missing intermediate; phone handsets, VPN clients and mail clients do not. Confirm it from outside with the SSL checker, and if a certificate and key will not pair, the key matcher says why in seconds.

Questions we get asked before people order

Will a normal SSL certificate really work on an appliance?

Yes. Anything that accepts a certificate and a private key takes an ordinary publicly trusted certificate — there is no special “device” product and nobody should sell you one. Some firmware wants PEM and some wants a PKCS#12 bundle; both come from the same order and we convert between them free.

The device is not reachable from the internet. Can it still have a certificate?

Yes, and it is routine. Domain control is proved by publishing a DNS record for your domain, not by anything answering on the device. The box can stay on an isolated management VLAN and still present a publicly trusted certificate.

How many certificates do I need for a rack of forty consoles?

One, if they share a domain. A wildcard covers unlimited subdomains and installs on as many devices as you like, which is why it beats buying singles at about the third device.

Our NAS offers a free certificate. Why would we pay?

If it can reach the internet on port 80 and you are happy renewing every 90 days, do not. People buy when the box is deliberately not internet-facing, when they want a one-year cycle instead of a quarterly one, or when one certificate has to cover a whole rack. We would rather tell you that than sell you something you do not need.

Not sure? Send us the list and we will price it up

Tell us the hostnames and what each box is. We come back with the cheapest combination that genuinely covers the estate — usually one multi-domain certificate, sometimes a wildcard plus extras — and we say so when that is fewer certificates than you were about to buy. No obligation, no sales call.