# Obtaining a trusted certificate for a vCenter 7 home lab

**URL:** https://community.letsencrypt.org/t/obtaining-a-trusted-certificate-for-a-vcenter-7-home-lab/187504
**Category:** Issuance Tech
**Created:** [November 8, 2022, 3:33pm UTC](https://community.letsencrypt.org/t/obtaining-a-trusted-certificate-for-a-vcenter-7-home-lab/187504 "2022-11-08T15:33:06Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![rmorrison3](https://avatars.discourse-cdn.com/v4/letter/r/4af34b/32.png) [@rmorrison3](https://community.letsencrypt.org/u/rmorrison3)
#### Post date: [November 8, 2022, 3:33pm UTC](https://community.letsencrypt.org/t/obtaining-a-trusted-certificate-for-a-vcenter-7-home-lab/187504/1 "2022-11-08T15:33:06Z")

</div>

Is there a place that I can just paste a CSR to get a certificate for a home lab that does not have a public facing IPv4 address?

---

<div class="post-metadata">

### Author: ![rmbolger](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rmbolger/32/27474_2.png) [@rmbolger](https://community.letsencrypt.org/u/rmbolger)
#### Post date: [November 8, 2022, 4:05pm UTC](https://community.letsencrypt.org/t/obtaining-a-trusted-certificate-for-a-vcenter-7-home-lab/187504/2 "2022-11-08T16:05:17Z")

</div>

Is your home lab using a domain name that you own and can control the internet-facing DNS records for? If not, then it doesn't matter whether you have a CSR or not. You can't get a publicly trusted certificate for an internal only domain name or a fake name you don't actually own. You would either have to setup your own internal certificate authority or just stick with the self-signed certs.

If it _is_ using a public domain name you can control the public DNS records for, then yes. There are plenty of ACME clients that can potentially use an existing CSR and ultimately get you a certificate. This will also involve you creating DNS TXT records either manually or with a plugin that supports your DNS provider.

---

<div class="post-metadata">

### Author: ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)
#### Post date: [November 8, 2022, 4:15pm UTC](https://community.letsencrypt.org/t/obtaining-a-trusted-certificate-for-a-vcenter-7-home-lab/187504/3 "2022-11-08T16:15:22Z")

</div>

You will want to look through these links

> [@Issuing Certificates to Internal Network](https://community.letsencrypt.org/t/issuing-certificates-to-internal-network/182155):
>
> I…

> [@Trusted SSL for private networks](https://community.letsencrypt.org/t/trusted-ssl-for-private-networks/149663):
>
> I…

> **[Build a Tiny Certificate Authority For Your Homelab](https://smallstep.com/blog/build-a-tiny-ca-with-raspberry-pi-yubikey/)**
>
> Let's make a tiny, standalone CA! We'll use a Raspberry Pi 4, YubiKey 5 NFC, and Infinite Noise TRNG.

Also searching for _private networks_ also _smallstep_ on this forum maybe helpful to you.

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)
#### Post date: [December 8, 2022, 4:16pm UTC](https://community.letsencrypt.org/t/obtaining-a-trusted-certificate-for-a-vcenter-7-home-lab/187504/4 "2022-12-08T16:16:12Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
