Devices & Servers · Intranet & internal applications
Get your internal sites trusted without exposing them to the internet
Browsers now treat an internal site with a self-signed certificate much like a hostile one — a full-page interstitial, and an exception that will not stay saved.
- Chrome keeps closing the door on self-signed internal sitesThe interstitial gets harder to bypass with each release, and running your own certificate authority means pushing a root to every device you own, including the ones you do not manage.
- Nothing has to face the internetValidation is done with a DNS record, so an internal-only hostname gets a publicly trusted certificate without exposing the service to anyone.
- One wildcard covers every internal hostwiki, jira, git, grafana and whatever you stand up next month — the same certificate file, no reissue, no new purchase.
- It works with split-horizon DNSThe certificate does not care what the name resolves to inside your network. Public trust on a private address.
- $121.98for a year, Comodo PositiveSSL...
- 25% offits list price of $162.64
- DNS validatednothing exposed to the internet
- Unlimited hostsone wildcard, every subdomain
Start with the application you need to fix
These all present a certificate on a hostname, which means they all take the same product. The only question is how many hostnames you have.
- SharePoint and staff portals intranet.acme.com Every internal application under one domain →
- Jira and Confluence jira.acme.com Every internal application under one domain →
- GitLab and Gitea git.acme.com Every internal application under one domain →
- Jenkins and CI runners ci.acme.com Every internal application under one domain →
- Grafana and Kibana metrics.acme.com Every internal application under one domain →
- Nextcloud and ownCloud cloud.acme.com One internal application →
- Odoo, ERP and CRM erp.acme.com One internal application →
- RDS Gateway and RemoteApp rds.acme.com One internal application →
- Citrix StoreFront apps.acme.com An auditor wants your company name in the certificate →
- Zabbix, Nagios, PRTG monitor.acme.com Every internal application under one domain →
- Internal wikis and helpdesks wiki.acme.com Every internal application under one domain →
- Dev and staging environments staging.acme.com Several unrelated internal domains →
How much of your internal estate are you covering?
Almost everyone lands on the first option. It is worth reading the other three before you assume it.
Every internal application under one domain
This is the answer for most companies. One wildcard, one file, and every internal host under the domain is covered — including the three you will stand up next quarter, with no reissue and no extra cost.
Typically: intranet, jira, git, ci, monitor and everything else under acme.com.
Comodo PositiveSSL Wildcard Certificate
Unlimited subdomains of one domain, issued in minutes. Buy once, install everywhere, add hosts freely for the rest of the term.
- Domain validated · issued in minutes
- Covers unlimited subdomains of the domain
- $10,000 warranty
- Free unlimited reissues for the whole term
Comodo EssentialSSL Wildcard Certificate
The same wildcard coverage under the EssentialSSL brand. Compare the two on the term you want.
- Domain validated · issued immediately
- Covers unlimited subdomains of the domain
- $10,000 warranty
One internal application
If a single app is the problem — the wiki everyone complains about, or the one tool that broke when Chrome tightened up — a single-name certificate is a few dollars and takes minutes.
Typically: One hostname, one internal application.
Comodo PositiveSSL Certificate
One hostname, publicly trusted, issued in minutes. Nothing to distribute to staff machines.
- Domain validated · issued in minutes
- $10,000 warranty
- Free unlimited reissues for the whole term
Comodo EssentialSSL Certificate
The same single-name coverage with immediate issuance under the EssentialSSL brand.
- Domain validated · issued immediately
- $10,000 warranty
- Free unlimited reissues for the whole term
An auditor wants your company name in the certificate
Internal systems handling regulated data are frequently required to carry organisation-validated certificates, so that the certificate itself names the legal entity operating the service. The wildcard coverage is the same; the vetting is not.
Typically: ISO 27001, PCI scope, client security questionnaires.
Certum Trusted Wildcard SSL Certificate
Organisation-validated wildcard at the lowest price we sell one for. Your registered company name inside, unlimited subdomains outside.
- Organisation validated · issued in 1-3 days
- Covers unlimited subdomains of the domain
- 400 000 € warranty
Comodo InstantSSL Premium Wildcard (OV)
The same organisation vetting with a larger warranty behind it, if the number in the policy matters.
- Organisation validated · issued in 1-3 days
- Covers unlimited subdomains of the domain
- $250,000 warranty
- Free unlimited reissues for the whole term
Several unrelated internal domains
Groups that have grown by acquisition usually end up with internal estates on three or four registered domains. One multi-domain wildcard covers each domain and everything beneath it, on one renewal date.
Typically: acme.com, acquired-brand.com and a legacy domain, subdomains under each.
PositiveSSL Multi-Domain Wildcard SSL Certificate
Several domains and unlimited subdomains under each, on one certificate and one expiry date.
- Domain validated · issued in minutes
- Covers unlimited subdomains of the domain
- 3 hostnames included, up to 247 in total
- $10,000 warranty
- Free unlimited reissues for the whole term
Comodo PositiveSSL Multi-Domain Certificate
Cheaper when you know exactly which hostnames you need and they are not going to grow. Names are listed explicitly rather than covered by a wildcard.
- Domain validated · issued in minutes
- 3 hostnames included, up to 247 in total
- $10,000 warranty
- Free unlimited reissues for the whole term
Read this before you order for an internal system
No public authority can certify .local, .internal or an IP address
This is the single most common blocker on this page. Since 1 November 2015 no certificate authority may issue for intranet, wiki.local, app.internal or 10.0.0.15. The fix is a naming change, not a different product: give the host a name under a domain you own, such as wiki.acme.com, and use split-horizon DNS so it resolves to the private address inside your network and to nothing outside it.
You do not have to expose the application to validate it
Domain control can be proved by publishing a TXT record in your public DNS. Nothing needs to answer on port 80 from the internet, and the application can stay entirely on the LAN or behind the VPN. This is what makes buying a public certificate practical for a system that is never internet-facing.
A private CA is a real option — with a real cost
You can run your own certificate authority instead. You then own distributing the root to every laptop, phone, tablet, contractor machine and container image, forever, and every device that misses it sees a worse warning than the one you started with. For most companies a wildcard is cheaper than the first month of that work.
Questions we get asked about this
Our app is only reachable on the LAN. Can we still get a certificate?
Yes, and it is routine. Validation happens against the public DNS for the domain, not against the application. As long as you control the domain, the host itself can stay entirely internal.
Does a wildcard cover deeper subdomains?
No. *.acme.com covers wiki.acme.com but not wiki.dev.acme.com. If you use a second level, you need a second wildcard for *.dev.acme.com or the names listed explicitly on a multi-domain certificate.
How many servers can we install one certificate on?
For the products on this page, install the same file on as many internal hosts as you like. Some enterprise ranges elsewhere on the site are licensed per server and say so on their product page — worth checking if you move up to one of those.
What if we rename hosts halfway through the term?
A wildcard does not care. On a multi-domain certificate you request a free reissue with the new list of names, which takes minutes for domain-validated products.
Something else on the network?
The same certificates cover the rest of the estate. These pages start from the hardware rather than from the certificate.
- Firewalls, VPN & routers FortiGate, SonicWall, Palo Alto, pfSense, Cisco ASA
- Voice: PBX, UCM & SBC Cisco UCM, 3CX, FreePBX, session border controllers
- Mail servers & webmail Exchange, autodiscover, Zimbra, smtp, imap
- Intranet & internal apps Staff portals, Jira, GitLab, dashboards, RDS
- NAS, hypervisor & consoles Synology, QNAP, VMware, Proxmox, iLO, iDRAC
- Web & app servers IIS, Apache, Nginx, Tomcat, load balancers
Send us the hostname list and we will price it up
Tell us what each box is and which names it answers on. We come back with the cheapest combination that genuinely covers the estate — and say so if that is fewer certificates than you were about to buy.