Strange that the main national domain registrar (http://manage.datacom.mn) yet don&#8217;t use SSL for own management console. Mobinet, national cloud provider even don&#8217;t have DNS registration for own services asking to create hosts file records for vps-mgnt.mobinet.mn. Mobinet who resells Comodo SSL doesn&#8217;t have valid SSL for https://vps-mgnt.mobinet.mn/ (and looks like self-signed SSL is created to conflict with vmware cert namespace). SSL providers suggest DNS (email) validation for certificate CSR, so vulnerable web DNS manager (not protected by SSL) can compromise issued SSL certs and finally web  <span><a href="https://www.itforce.mn/index.php/2017/05/06/696/" class="readmore">Continue reading &rarr;</a></span>{"id":696,"date":"2017-05-06T14:20:52","date_gmt":"2017-05-06T06:20:52","guid":{"rendered":"http:\/\/www.itforce.mn\/?p=696"},"modified":"2017-06-13T13:12:01","modified_gmt":"2017-06-13T05:12:01","slug":"696","status":"publish","type":"post","link":"https:\/\/www.itforce.mn\/index.php\/2017\/05\/06\/696\/","title":{"rendered":"Free ComodoSSL, free &#8220;Let&#8217;s encrypt&#8221; certificates"},"content":{"rendered":"<div id=\"ember7152\" class=\"feed-s-update__description feed-s-inline-show-more-text ember-view\">\n<p id=\"ember7157\" class=\"Sans-15px-black-70% feed-s-main-content ember-view\" dir=\"ltr\"><span id=\"ember7164\" class=\"ember-view\">Strange that the main national domain registrar (<\/span><a id=\"ember7167\" class=\"feed-link ember-view\" href=\"http:\/\/manage.datacom.mn\" target=\"_blank\" rel=\"noopener noreferrer\">http:\/\/manage.datacom.mn<\/a><span id=\"ember7169\" class=\"ember-view\">) yet don&#8217;t use SSL for own management console. Mobinet, national cloud provider even don&#8217;t have DNS registration for own services asking to create hosts file records for vps-mgnt.mobinet.mn. Mobinet who resells Comodo SSL doesn&#8217;t have valid SSL for\u00a0<\/span><a href=\"https:\/\/vps-mgnt.mobinet.mn\/\">https:\/\/vps-mgnt.mobinet.mn\/<\/a><span id=\"ember7174\" class=\"ember-view\"> (and looks like self-signed SSL is created to conflict with vmware cert namespace). <\/span><\/p>\n<p class=\"Sans-15px-black-70% feed-s-main-content ember-view\" dir=\"ltr\"><span id=\"ember7174\" class=\"ember-view\">SSL providers suggest DNS (email) validation for certificate CSR, so vulnerable web DNS manager (not protected by SSL) can compromise issued SSL certs and finally web sites with online banking, payment systems and so on. I suggest for low-budget , non-critical or experimental sites to use at least free SSL certs from <\/span><a id=\"ember7177\" class=\"feed-link ember-view\" href=\"https:\/\/zerossl.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/zerossl.com\/<\/a><span id=\"ember7179\" class=\"ember-view\"> &#8211; better than absence or wrong SSL certs. <\/span><\/p>\n<p class=\"Sans-15px-black-70% feed-s-main-content ember-view\" dir=\"ltr\"><span id=\"ember7179\" class=\"ember-view\">If main key security players are neglect in own responsibilities, what to say about others.<\/span><\/p>\n<p class=\"Sans-15px-black-70% feed-s-main-content ember-view\" dir=\"ltr\"><a href=\"https:\/\/www.mobicom.mn\/en\/m\/246\">Price from Mobinet\u00a0<\/a> for Comodo instantSSL is 360 000 mnt + 50 000 mnt (for installation) = 410 000 mnt (about 150-170 usd per year) :<\/p>\n<p class=\"Sans-15px-black-70% feed-s-main-content ember-view\" dir=\"ltr\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-699\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/05\/resold-comodo.jpg\" alt=\"\" width=\"1002\" height=\"398\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/05\/resold-comodo.jpg 1002w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/05\/resold-comodo-300x119.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/05\/resold-comodo-768x305.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/05\/resold-comodo-624x248.jpg 624w\" sizes=\"auto, (max-width: 1002px) 100vw, 1002px\" \/><\/p>\n<\/div>\n<p class=\"Sans-15px-black-70% feed-s-main-content ember-view\" dir=\"ltr\">If you buy directly from Comodo 77 usd per year:<\/p>\n<p class=\"Sans-15px-black-70% feed-s-main-content ember-view\" dir=\"ltr\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-698\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/05\/comodo-direct.jpg\" alt=\"\" width=\"1273\" height=\"871\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/05\/comodo-direct.jpg 1273w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/05\/comodo-direct-300x205.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/05\/comodo-direct-768x525.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/05\/comodo-direct-1024x701.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/05\/comodo-direct-624x427.jpg 624w\" sizes=\"auto, (max-width: 1273px) 100vw, 1273px\" \/><\/p>\n<p class=\"Sans-15px-black-70% feed-s-main-content ember-view\" dir=\"ltr\">If you have any questions how to install\u00a0 free &#8220;Let&#8217;s encrypt&#8221; SSL, free Comodo SSL for 90 days, or how to buy, install, configure long-term SSL for your web site feel free to contact with me.<\/p>\n<p dir=\"ltr\">To auto renew &#8220;Let&#8217;s encrypt&#8221; free SSL read my <a href=\"http:\/\/www.itforce.mn\/index.php\/2017\/06\/13\/how-to-auto-renew-lets-encrypt-free-certificate-extending-90-days-limit\/\">next post<\/a><\/p>\n<p class=\"Sans-15px-black-70% feed-s-main-content ember-view\" dir=\"ltr\">ps.<\/p>\n<p class=\"Sans-15px-black-70% feed-s-main-content ember-view\" dir=\"ltr\">Useful links:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.startcomca.com\">https:\/\/www.startcomca.com<\/a><\/li>\n<li><a href=\"https:\/\/zerossl.com\/\">https:\/\/zerossl.com\/<\/a><\/li>\n<li><a href=\"https:\/\/letsencrypt.org\/\">https:\/\/letsencrypt.org\/<\/a><\/li>\n<li><a href=\"https:\/\/www.positivessl.com\/free-secure-email-certificates.php?key5sk1=dec9c8d183e8373cf33d1abd6151530d9568f607\">https:\/\/www.positivessl.com\/free-secure-email-certificates.php?key5sk1=dec9c8d183e8373cf33d1abd6151530d9568f607<\/a><\/li>\n<li><a href=\"https:\/\/www.sslforfree.com\/\">https:\/\/www.sslforfree.com\/<\/a><\/li>\n<li><a href=\"https:\/\/www.symantec.com\/theme\/encryption-everywhere\">https:\/\/www.symantec.com\/theme\/encryption-everywhere<\/a><\/li>\n<li><a href=\"https:\/\/pantheon.io\/docs\/guides\/cloudflare-enable-https\/\">https:\/\/pantheon.io\/docs\/guides\/cloudflare-enable-https\/<\/a><\/li>\n<li><a href=\"https:\/\/collectiveidea.com\/blog\/archives\/2016\/09\/22\/free-ssl-on-heroku\">https:\/\/collectiveidea.com\/blog\/archives\/2016\/09\/22\/free-ssl-on-heroku<\/a><\/li>\n<li><a href=\"https:\/\/www.register.com\/product\/security-sslcertificates.rcmx\">https:\/\/www.register.com\/product\/security-sslcertificates.rcmx<\/a><\/li>\n<li><a href=\"https:\/\/www.mobicom.mn\/en\/m\/246\">https:\/\/www.mobicom.mn\/en\/m\/246<\/a><\/li>\n<li><a href=\"https:\/\/www.namecheap.com\/security\/ssl-certificates\/domain-validation.aspx\">https:\/\/www.namecheap.com\/security\/ssl-certificates\/domain-validation.aspx<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":null,"protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,5,7],"tags":[],"class_list":["post-696","post","type-post","status-publish","format-standard","hentry","category-it-governance","category-security","category-sysadmin-thoughts"],"_links":{"self":[{"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/posts\/696","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/comments?post=696"}],"version-history":[{"count":10,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/posts\/696\/revisions"}],"predecessor-version":[{"id":735,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/posts\/696\/revisions\/735"}],"wp:attachment":[{"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/media?parent=696"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/categories?post=696"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/tags?post=696"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}