Re: [openssl-users] Non-self-signed SSL certificates for private hosted DNS zones

2017-03-07 Thread Traiano Welcome
Hi Viktor Thanks for this confirmation. I think the correct approach would be to use our internal CA. On Tue, Mar 7, 2017 at 7:16 PM, Viktor Dukhovni <openssl-us...@dukhovni.org> wrote: > > > On Mar 7, 2017, at 2:21 AM, Traiano Welcome <trai...@gmail.com> wrote: > &g

[openssl-users] Non-self-signed SSL certificates for private hosted DNS zones

2017-03-06 Thread Traiano Welcome
Hi List I have a private DNS zone hosted on AWS route 53, only resolvable from within some specific VPCs. It appears some applications require an SSL certificate associated with the private DNS zone, and this SSL certificate should come from a trusted, external certificate provider (cannot be