Devices & Servers · Intranet & internal applications

Get your internal sites trusted without exposing them to the internet

Browsers now treat an internal site with a self-signed certificate much like a hostile one — a full-page interstitial, and an exception that will not stay saved.

  • Chrome keeps closing the door on self-signed internal sitesThe interstitial gets harder to bypass with each release, and running your own certificate authority means pushing a root to every device you own, including the ones you do not manage.
  • Nothing has to face the internetValidation is done with a DNS record, so an internal-only hostname gets a publicly trusted certificate without exposing the service to anyone.
  • One wildcard covers every internal hostwiki, jira, git, grafana and whatever you stand up next month — the same certificate file, no reissue, no new purchase.
  • It works with split-horizon DNSThe certificate does not care what the name resolves to inside your network. Public trust on a private address.
  • $121.98for a year, Comodo PositiveSSL...
  • 25% offits list price of $162.64
  • DNS validatednothing exposed to the internet
  • Unlimited hostsone wildcard, every subdomain

Start with the application you need to fix

These all present a certificate on a hostname, which means they all take the same product. The only question is how many hostnames you have.

How much of your internal estate are you covering?

Almost everyone lands on the first option. It is worth reading the other three before you assume it.

1

Every internal application under one domain

This is the answer for most companies. One wildcard, one file, and every internal host under the domain is covered — including the three you will stand up next quarter, with no reissue and no extra cost.

Typically: intranet, jira, git, ci, monitor and everything else under acme.com.

Best for this COMODO

Comodo PositiveSSL Wildcard Certificate

Unlimited subdomains of one domain, issued in minutes. Buy once, install everywhere, add hosts freely for the rest of the term.

  • Domain validated · issued in minutes
  • Covers unlimited subdomains of the domain
  • $10,000 warranty
  • Free unlimited reissues for the whole term
from $121.98 $162.64 per year, before term discounts
Details
Also fine COMODO

Comodo EssentialSSL Wildcard Certificate

The same wildcard coverage under the EssentialSSL brand. Compare the two on the term you want.

  • Domain validated · issued immediately
  • Covers unlimited subdomains of the domain
  • $10,000 warranty
from $131.61 $175.48 per year, before term discounts
Details
2

One internal application

If a single app is the problem — the wiki everyone complains about, or the one tool that broke when Chrome tightened up — a single-name certificate is a few dollars and takes minutes.

Typically: One hostname, one internal application.

Best for this COMODO

Comodo PositiveSSL Certificate

One hostname, publicly trusted, issued in minutes. Nothing to distribute to staff machines.

  • Domain validated · issued in minutes
  • $10,000 warranty
  • Free unlimited reissues for the whole term
from $14.99 $49 per year, before term discounts
Details
Also fine COMODO

Comodo EssentialSSL Certificate

The same single-name coverage with immediate issuance under the EssentialSSL brand.

  • Domain validated · issued immediately
  • $10,000 warranty
  • Free unlimited reissues for the whole term
from $21.18 $28.24 per year, before term discounts
Details
3

An auditor wants your company name in the certificate

Internal systems handling regulated data are frequently required to carry organisation-validated certificates, so that the certificate itself names the legal entity operating the service. The wildcard coverage is the same; the vetting is not.

Typically: ISO 27001, PCI scope, client security questionnaires.

Best value OV wildcard CERTUM

Certum Trusted Wildcard SSL Certificate

Organisation-validated wildcard at the lowest price we sell one for. Your registered company name inside, unlimited subdomains outside.

  • Organisation validated · issued in 1-3 days
  • Covers unlimited subdomains of the domain
  • 400 000 € warranty
from $129 $398 per year, before term discounts
Details
Premium OV wildcard COMODO

Comodo InstantSSL Premium Wildcard (OV)

The same organisation vetting with a larger warranty behind it, if the number in the policy matters.

  • Organisation validated · issued in 1-3 days
  • Covers unlimited subdomains of the domain
  • $250,000 warranty
  • Free unlimited reissues for the whole term
from $274 $449 per year, before term discounts
Details
4

Several unrelated internal domains

Groups that have grown by acquisition usually end up with internal estates on three or four registered domains. One multi-domain wildcard covers each domain and everything beneath it, on one renewal date.

Typically: acme.com, acquired-brand.com and a legacy domain, subdomains under each.

Best for this COMODO

PositiveSSL Multi-Domain Wildcard SSL Certificate

Several domains and unlimited subdomains under each, on one certificate and one expiry date.

  • Domain validated · issued in minutes
  • Covers unlimited subdomains of the domain
  • 3 hostnames included, up to 247 in total
  • $10,000 warranty
  • Free unlimited reissues for the whole term
from $267.24 $356.32 per year, before term discounts
Details
If the host list is fixed COMODO

Comodo PositiveSSL Multi-Domain Certificate

Cheaper when you know exactly which hostnames you need and they are not going to grow. Names are listed explicitly rather than covered by a wildcard.

  • Domain validated · issued in minutes
  • 3 hostnames included, up to 247 in total
  • $10,000 warranty
  • Free unlimited reissues for the whole term
from $114 $165 per year, before term discounts
Details

Read this before you order for an internal system

No public authority can certify .local, .internal or an IP address

This is the single most common blocker on this page. Since 1 November 2015 no certificate authority may issue for intranet, wiki.local, app.internal or 10.0.0.15. The fix is a naming change, not a different product: give the host a name under a domain you own, such as wiki.acme.com, and use split-horizon DNS so it resolves to the private address inside your network and to nothing outside it.

You do not have to expose the application to validate it

Domain control can be proved by publishing a TXT record in your public DNS. Nothing needs to answer on port 80 from the internet, and the application can stay entirely on the LAN or behind the VPN. This is what makes buying a public certificate practical for a system that is never internet-facing.

A private CA is a real option — with a real cost

You can run your own certificate authority instead. You then own distributing the root to every laptop, phone, tablet, contractor machine and container image, forever, and every device that misses it sees a worse warning than the one you started with. For most companies a wildcard is cheaper than the first month of that work.

Questions we get asked about this

Our app is only reachable on the LAN. Can we still get a certificate?

Yes, and it is routine. Validation happens against the public DNS for the domain, not against the application. As long as you control the domain, the host itself can stay entirely internal.

Does a wildcard cover deeper subdomains?

No. *.acme.com covers wiki.acme.com but not wiki.dev.acme.com. If you use a second level, you need a second wildcard for *.dev.acme.com or the names listed explicitly on a multi-domain certificate.

How many servers can we install one certificate on?

For the products on this page, install the same file on as many internal hosts as you like. Some enterprise ranges elsewhere on the site are licensed per server and say so on their product page — worth checking if you move up to one of those.

What if we rename hosts halfway through the term?

A wildcard does not care. On a multi-domain certificate you request a free reissue with the new list of names, which takes minutes for domain-validated products.

Something else on the network?

The same certificates cover the rest of the estate. These pages start from the hardware rather than from the certificate.

Send us the hostname list and we will price it up

Tell us what each box is and which names it answers on. We come back with the cheapest combination that genuinely covers the estate — and say so if that is fewer certificates than you were about to buy.