Forum Moderators: buckworks & webwork

10K+ sub-domains - cannot afford SSL

         

KenSA

10:25 am on Sep 29, 2025 (gmt 0)



G'Day From Barossa Goldfields South Australia.

- I used to be part of the team who managed the most popular web site in southern hemisphere & it was not based on a CMS
- For last 25 years been building mainly socket apps, usually in C
- I built my 1st web site mid '90s
- Have been self hosting since, usually only port 25 & 80

So I have a lot of experience with web services etc. etc. etc., but having now built 10,000+ 1 page 'Go Pages' (GPs) using VB each based on a different sub-domain I just got a quote for many millions of dollars for a certif. for each sub-dom.

If your solution is a wildcard SSL pls. don't reply, I'm long past that :)

I need advise from someone who has experience buying 10K SSLs ( Wholesale ) as we will have ~200K sub-domains eventually

BTW - These GPs are only for use in Australia, so not interested in SEO or indexing or security

Brett_Tabke

12:43 pm on Sep 29, 2025 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



First, thanks for checking here. Sounds like a fascinating project!

> vb

What in asp? Care to share more info?

You are in rare territory with that size of sites is going to be next to impossible to find cheaper.

What did that work out to per certificate?

KenSA

1:38 pm on Sep 29, 2025 (gmt 0)



G'Day BT

Thanks for a very prompt reply, aren't you supposed to be working as ITs Mon. AM in US, get bak 2 wrk u bum :)

No Visual Basic 6 on a Win. Server using API to monitor folders populated by FTP of a IBM DB for web site re-direct persistence ( worlds best replication engin ), as I have been writing code for 50 years I have lots of proof of concept / 'abandonware' & this project was my 1st attempt at AI started 15 years ago so IT was very easy to hack the code base & produce GPs by the 1000s - basically I'm working on Jeff Bezos 'get big fast' so I don't get swamped.

In a nutshell, the system is all about being hyperlocal & can be used for

- Disaster Monitoring , Mitigation & Recovery - ( Primary Design Consideration )
- Allow local gov. to develop alternate revenue streams
- Australians are mad about real estate & allow them to rent their prop. via a GEO local ! a US database
- Allow a business to prompt other businesses in their local gov. area as well as themselves without SEO
- Permit ppl to order from a local & don't pay the full purchase price, C$$H economy pay a deposit with orders & bal. before dispatch

A irBnB
A mazon
G oogle
e Bay
D isrupted

I'm ! happy to reveal a price / SSL at this stage, I want the SSL 4 free or a few 'pennies' as I don't really need them just getting hassled by a angel investor. Plus applying that many will be a tad boring !

As the AI is initially grabbing all the data from Google Business Profiles ( GBP ) ATM there is no DB like with a CMS, the only 'typical' DB is the DNS sub-doms & I'm thinking about setting up a root server that is only avail. in .au

Yes very interesting, last sys. before I retire & go fishing in the southern ocean

Brett_Tabke

2:15 pm on Sep 29, 2025 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Sounds fascinating - wish I could help.

KenSA

8:52 pm on Sep 29, 2025 (gmt 0)



G'Day BT

I noticed a long time ago AI bots have no concept of 'normal' working hours, WFH or anything about a commute to or from an office :)

In no particular order

- Go is a recursive acronym for Go oH

- Spammers only try & guess the mailbox, never the sub-dom(s) - I have confirmed this over 25 plus years & never had a spam delivered since analysis of SMTP log like this fragment below revealed

29/09/2025 11:29:21 PM N S A 3: SMTP '94' - 'no hostname' (103.15.222.75)
29/09/2025 11:29:21 PM N S A 3: SMTP '94' - '2' sessions blocked IP '103.15.222.75'
29/09/2025 11:29:21 PM N S A 3: SMTP '94' - TCPIP '103.15.222.75' - 'NO HOSTNAME' - Marking TCPIP as BLed
29/09/2025 11:29:22 PM SMTP Server: 103.15.222.75 connected
29/09/2025 11:29:22 PM N S A 3: SMTP '94' - 'ehlo newyorkprisonconsultants.com'
29/09/2025 11:29:22 PM N S A 3: SMTP '94' - 'mail from:<aria@newyorkprisonconsultants.com>'
29/09/2025 11:29:22 PM N S A 3: SMTP '94' - 'rcpt to:<god@ [REDACTED] >'
29/09/2025 11:29:22 PM N S A 3: SMTP '94' - 'data'
29/09/2025 11:29:23 PM SMTP Server: 103.15.222.75 disconnected. 0 message[s] received 

- If you don't use .php files ITs very easy to check for them in a HTTP log of error 404 Not Found category & BL those TOR exits

- Sub-Doms will set you free to iframe "friends & family" content - as in FREEdom

- In Australia ITs illegal to rent or sell sub-doms, but you can 'give' them away as a FREEdom

- Go is a recursive acronym for Go Ogle

KenSA

9:23 pm on Sep 29, 2025 (gmt 0)



Sorry forgot to mention my favorite down stream of sub-doms - how many Steganography Stegocontainers can I have in 10K of sub-doms GPs

Then think how many in 100K of SDs GPs

That would keep No Spam Accepted ( N S A ) busy for a few hours / days / weeks maybe ?

tangor

4:46 am on Sep 30, 2025 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Gotta say two things:

Welcome to Webmasterworld...

Give me a beer, I think I am out of my league.

Good luck on the SSL Certs!

mack

3:54 pm on Sep 30, 2025 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



I am clearly out of my depth with that many subdomains, but is there a specific reason you need to use commercial SSL certs as opposed to free certs from a provider like Let's Encrypt?

I accept that free SSL's aren't as good as commercial ones, but it would keep web browsers happy and remove "insecure" warnings.

I imagine you have a good reason for not wanting to go down this route, but it may be a solution (if only temporary)?

Mack.

KenSA

2:51 am on Oct 1, 2025 (gmt 0)



G'Day Mack

I am clearly out of my depth with that many subdomains, but is there a specific reason you need to use commercial SSL certs as opposed to free certs from a provider like Let's Encrypt?


[Ken] Good question well asked mate, no your ! out of your depth, sub-doms on this scale is scary for every1, we didn't want 2 have 2 create a txt for each & every SD remember there could be 200K ( so that means these SD wouldn't exist ) we are already using Round Robin DNS so then the question becomes how to resolve something that doesn't exist, except on the Go HTTP servers, so if you 'hack' a DNS client / server & allow for a wildcard resolution then the HTTP server takes care of spelling mistakes / typos eg [Pengiun.7o.au...] instead of [Penguin.7o.au...] - let me go off on a tangent here - you currently have to enter http:// because we have no SSLs, 7o is said 7Go but u don't type the G & 7 is the first # in all of Tasmania's (TAS) postcodes, which to you guys from USA is a zip code, but ours are only 4 digits '9999' not 5 digits so this is why Ogle SD design cant scale up in USA ATM without a fundamental re-design of the TLD 2o ( NSW ) , 3o ( VIC ) , 4o ( QLD ) , 5o ( SA ) , 6o ( WA ) ... this is just not going to work when Zips are like 90210 & we only have 10 'states'

[Ken] Short answer, this angel bought BC in '13 when they were 'free' so they are R$$H & we don't want to offer a cheap option to them ATM :)

[Ken] We need WAN aware investors, who are going to be Hyper Local & bring a large group of contacts from their state to the table, this is all part of our "brand before you build" philosophy - we call them State Go Guardians ( SGG ) - which I know is kind of 'creepy' but the CEO is my wife & 'she who must be obeyed' - so I'm happy for you guys to contact her & tell her you don't think this is professional etc. , I will stand at the door & make certain she doesn't escape while u give her a piece of your mind :)


I accept that free SSL's aren't as good as commercial ones, but it would keep web browsers happy and remove "insecure" warnings.


[Ken] We just want to get the "insecure" warning to go away, this system is designed to be used during a natural disaster, so we won't be using a login / pwd pair for any1 we need IT to be as simple as possible because the 'customer' will probably be under hugh pressure, but we need to feed the AI with "Yes I can smell the smoke from the bush fire", "Yes I can see the flames from the bush fire" , "Yes" my dog is hiding !

[Ken] We don't have earth quakes ( well almost ) in Oz, unlike in the USA, but I know from when I lived in Minnesota ( Little Apple ) that Dogs ( a mans best friend ) seem to know when they are about o 'hit', so we are looking to get local government to export their dog. registration DBs & we will turn that into Go Pages, this is why each page is less than 2mb & why they render so fast & we never need to archive our web servers. We currently use AI to mine Google Bus. Profile ( GBP ) for all of the text we have inside of the HTML so do we really need SSLs ?


I imagine you have a good reason for not wanting to go down this route, but it may be a solution (if only temporary)?


[Ken] We don't go live until 12 / 12 / 25 so everything is temp. ATM, just working thru. the incidents, so I will try some free SSL & try & find a down side, but we are already 'conning' the customers, because the Sub-dom ( TXT records ) will not exist in a DNS server, so IT seems crazy to them show them a key & pretend they are 'safe'

[Ken] Now you understand a little more about why Go Group is so confused, we don't even have a good name for the WAN that doesn't exist, absolutely not using Dark Web, maybe 'invisible web' , 'Oz only web' , 'JIT WAN' , "iWAN' these are some of the better ideas,


TIA

KSA

KenSA

4:41 pm on Oct 25, 2025 (gmt 0)



Did any1 else see AWS 'DNS Outage' recently ?


In Australia we have a x-CIA agent pretending to tell us how to parent our children & we need to prove we are all over 16, when I posted in an exclusive Australian only 'job' board I get a phone call saying what I'm looking to do is illegal because IT would mean our subdomains are 'uncontrollable" due to use having hacked the DNS servers.

I might be getting paranoid here, but I'm going to put "HTTPS" on hold & go bak to the DNS wildcard project to see if eKaren - "eSafety Commissioner is currently led by Commissioner Julie Inman Grant" who BTW has 'resigned' even before her hugely expensive US Bug ( ! Big ) tech project is launched comes a knocking on my door again

I will update here ASAP

[edited by: not2easy at 5:58 pm (utc) on Oct 25, 2025]
[edit reason] Please see TOS [webmasterworld.com] [/edit]