How to apply for an SSL certificate for free

How to apply for an SSL certificate for free

foreword

We can successfully bind the domain name we purchased to the data tunnel connected to the local Synology NAS, so that we can use a specific domain name on the public Internet to access the Synology NAS on the intranet with the help of cpolar . However, due to the use of the http protocol, such access connections are likely to be targeted by hackers. In order to avoid this situation, we need to upgrade the http protocol to https protocol. It is not complicated to upgrade the https protocol. From the process point of view, it is mainly divided into the domain name platform part and the cpolar client part. Now, let's take a look at how to deal with the domain platform part of the settings.

1. Apply for an SSL certificate from the domain name platform

The https protocol is an upgraded version of the http protocol. The main security measure is to add an encryption algorithm to the transmitted data, which can ensure the security of the transmitted data as much as possible. To obtain an encryption algorithm, you need to apply for an SSL certificate from the domain name platform. First go back to the domain name console of the domain name platform, click "Workbench" at the top of the page, and after entering the workbench page, click "SSL Certificate" (our domain name is purchased on the Alibaba Cloud platform, so we will use Alibaba Cloud as an example to introduce)

img

img

1.1 Purchasing "Free Certificate"

After entering the SSL certificate page, we select the "Free Certificate" item and click "Buy Now". Since each account can get 20 free certificates per year, we can directly click "Buy Now".

img

On the certificate purchase page, just click on the necessary information as shown in the picture below, and then click "Buy Now" at the bottom of the page.

img

2. Further create certificate settings

Then we return to the previous "Free Certificate" page, and next to the "Buy Now" item, the "Create Certificate 20/20" item is displayed. After clicking this item, we can continue to make further settings for the free certificate.

img

2.1 Supplement the associated domain name of the certificate

After clicking "Create Certificate", we need to supplement the associated domain name of the certificate on the pop-up webpage. The information that needs to be supplemented here includes: bound domain name (fill in the domain name you want to add a certificate to); domain name verification method (here select "manual DNS verification"); contact person (here will automatically associate the information of the domain name holder) and location information. Other key algorithms and CSR generation methods can remain the default options. Then click "Next" at the bottom of the page.

img

At this time, Alibaba Cloud will generate several information for verifying DNS, including "record type", "host record" and "record value". We need to be familiar with these pieces of information (which will be used in the next verification process). Among them, it is best to copy the record value for backup, and then click the "Verify" button at the bottom of the page to send a verification application to Alibaba Cloud.

img

3. Cloud Resolution DNS

Then we go back to the Alibaba Cloud workbench and click on the "Cloud Resolution DNS" option

img

On the "Apsara DNS" page, click the blue "Add Record" to verify the domain name association of the security certificate we applied for

img

3.1 Verify information

On the "Add Record" page, we need to fill in the verification information obtained before (Verify DNS page) into this page (this is also the origin of manual DNS verification), after confirming that the filling is correct, click the "Confirm" button at the bottom right to complete verification process.

img

img

At this point, the domain name platform setting for applying for an SSL security certificate for our domain name is complete. For the rest of the time, we only need to wait for the verification to pass. After the verification is passed, we can proceed to the next step, which is to set up the cpolar client. Due to space limitations, we will show you this part in detail in the next introduction. If you have any questions about the use of cpolar, please contact us, we will provide you with assistance within our ability. Of course, you are also welcome to join the VIP official group of cpolar to explore the unlimited potential of cpolar together.

Reprinted from the cpolar article: [Apply for a free SSL certificate for a custom domain name of a remote Synology NAS] (Apply for a free SSL certificate for a custom domain name of a remote Synology NAS-cpolar cloud )

Guess you like

Origin blog.csdn.net/2301_78420308/article/details/132148407