Wildcard certificates in the LANCOM Content Filter

As of LCOS 9.00 you have the possibility of using wildcard certificates in the LANCOM Content Filter. 





Allow wildcard certificates
With this feature enabled, Web sites with wildcard certificates (consisting of CN entries such as *.mydomain.com) are verified using the main domain (mydomain.com). Verification is evaluated in this sequence:
  • Server name check in the "Client Hello" (depends on the browser used)
  • Check of the CN in the SSL certificate that you received
  • Entries with wildcards are ignored
  • If the CN cannot be verified, the field "Alternative Name"is evaluated.
  • DNS reverse lookup of the associated IP address and verification of the host name obtained
  • If wildcards are included in the certificate, the main domain is checked instead (corresponds to the above function)
  • Verification of the IP address