You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When visiting one of created in Cosmos-Server URLs like something.servegame.com,
cert info of the website shows list of all added domains for other services: name.xyz something.servegame.com
What should have happened?
Cert info must show only corresponded domain and never list all added domains from other added to Cosmos-Server services
One domain = one cert.
How to reproduce the bug?
Having "Configuration > HTTP > Hostname" name.xyz
Go to "Management > URLs > Create, then go to new record's Setup > Use host" and specify different domain name you own, like something.servegame.com
Relevant log output
No response
Other details
No response
System details
OS: [any]
Browser [any]
Version [latest]
The text was updated successfully, but these errors were encountered:
azukaar
changed the title
[BUG]: security issue: cosmos getting one letsencrypt cert for multiple different domains
[BUG]: Cosmos getting one letsencrypt cert for multiple different domains
Oct 7, 2024
This is the intended behaviour, Cosmos does not support per-domain certificate
It is not a "security issue" or an issue at all for 99.99% cases.
I will leave the ticket opened for visibility, but at the moment splitting the cert is a very low priority item
azukaar
changed the title
[BUG]: Cosmos getting one letsencrypt cert for multiple different domains
[Feat]: Cosmos getting one letsencrypt cert for multiple different domains
Oct 7, 2024
What happened?
(domain names are redacted)
When visiting one of created in Cosmos-Server URLs like
something.servegame.com
,cert info of the website shows list of all added domains for other services:
name.xyz
something.servegame.com
What should have happened?
Cert info must show only corresponded domain and never list all added domains from other added to Cosmos-Server services
One domain = one cert.
How to reproduce the bug?
name.xyz
something.servegame.com
Relevant log output
No response
Other details
No response
System details
The text was updated successfully, but these errors were encountered: