| ▲ | stackghost 8 hours ago | |||||||
>so still no way to support TLS for LAN devices without manual setup or angering security researchers. Arguably setting up letsencrypt is "manual setup". What you can do is run a split-horizon DNS setup inside your LAN on an internet-routable tld, and then run a CA for internal devices. That gives all your internal hosts their own hostname.sub.domain.tld name with HTTPS. Frankly: it's not that much more work, and it's easier than remembering IP addresses anyway. | ||||||||
| ▲ | tosti 7 hours ago | parent | next [-] | |||||||
> run a CA > easier than remembering IP addresses idk, the 192.168.0 part has been around since forever. The rest is just a matter of .12 for my laptop, .13 for the one behind the telly, .14 for the pi, etc. Every time I try to "run a CA", I start splitting hairs. | ||||||||
| ||||||||
| ▲ | cpach 7 hours ago | parent | prev [-] | |||||||
There’s also the DNS-01 challenge that works well for devices on private networks. | ||||||||