SOHO https:// login fails

On a security recommendation, I attempted to configure my SOHO to accept an https login (http login works normally). One of the advanced network pages allows this option. The result is that both Firefox and IE fail with the error message the the certificate is for a different web site and the login will not proceed unless an exception is made.

Any ideas on which certificate would allow an https:// login?
Thank you,
Sparky5

You can manage the certs on the SOHO from Advanced > Misc. Settings > Certificate Manager. The Web Admin SSL cert is the one that will need to be updated. If youā€™re managing the device using IC2 you can take advantage of Letā€™s Encrypt integration.

From the device level in IC2 click on Edit.

image

Scroll down to the Find My Peplink Service and enable it. More options will show up. By default the Peplink DNS record will be the [serial number].my.peplink.link. Check the Manage Web Admin SSL Cert box and save. This will generate a cert using Letā€™s Encrypt every 76 days and push it to your device.

1 Like

Thanks. Generating a special certificate makes sense. Iā€™m just an individual non-network user and donā€™t have IC2 running. Is this the only way to produce a valid certificate?

Regards,
Sparky5

1 Like

You can first trust the certificate (see link). Then you can login into the Web Admin again. If you want, you could upload your own certificate under Advanced - Misc. Settings - Certificate Manager. When that works, the ā€˜invalidā€™ certificate can be removed from the trusted certificates in your browser.

192.168.20.1 does nothing, because the http address of the router is one IP address in the 10.xxx range. Login is normal using this one http router IP address to access administration. Attempted https:// logins fail. Error returned by the browser says:

ā€œThe certificate is only valid for the following names: captive-portal.peplink.com, www.captive-portal.peplink.com Error code: SSL_ERROR_BAD_CERT_DOMAINā€
I appreciate knowing about InControl, but I have no use for cloud based router administration. Iā€™m also confused about why Google should be used in any process related to the Peplink router?

Thanks,
Sparky5

The latest suggestion is to generate my own certificate and upload it to the router. I can see the certificate manager in FireFox ā€œOptionsā€ and it allows uploading certificates to its trusted list. I have no idea how to generate my personal security certificate. Not much to go on in the SOHO userā€™s manual.
Thanks!
Sparky5

A ā€œSSL Certificate Providerā€ like Comodo, GoDaddy, GlobalSign, ā€¦ can provide one. Or you can create a ā€œSelf Signed Certificateā€, as can be found on this forum post:

That is not Google. Itā€™s just a piece of Google Maps, that is used in InControl, that sneaked into the screenshot.

1 Like