←back to thread

314 points Bogdanp | 1 comments | | HN request time: 0s | source
Show context
vkdelta ◴[] No.44380805[source]
Does it help getting encrypted https (without self signed cert error) on my local router ? 192.168.0.1 being an example login page.
replies(6): >>44380853 #>>44380871 #>>44380923 #>>44381115 #>>44381757 #>>44382265 #
dark-star ◴[] No.44382265[source]
no but you can do something closely related:

- get a domain name (foo.com) and get certificates for *.foo.com

- run a DNS resolver that maps a.b.c.d.foo.com (or a-b-c-d.foo.com) to the corresponding private IP a.b.c.d

- install the foo.com certificate on that private IP's device

then you can connect to devices in your local network via IP by using https ://192-18-1-1.foo.com

Since you need to install the certificate in step 3 above, this works better with long-lived certificates, of course, but aotomation helps there

replies(2): >>44382457 #>>44383727 #
michaelt ◴[] No.44382457[source]
I considered doing that for a project once.

Then I realised that when my internet was down, 192-18-1-1.foo.com wouldn't resolve. And when my internet is down is exactly when I want to access my router's admin page.

I decided simply using unencrypted HTTP is a much better choice.

replies(1): >>44382624 #
yjftsjthsd-h ◴[] No.44382624{3}[source]
> Then I realised that when my internet was down, 192-18-1-1.foo.com wouldn't resolve.

Just add a local DNS entry on your local DNS server (likely your router).

replies(2): >>44382837 #>>44385344 #
1. jeroenhd ◴[] No.44385344{4}[source]
You don't even need to, mDNS has been enabled by default by most devices for ages now. You'll have to look up what the name is your manufacturer chose (if you use Windows, you van usually hit the network explorer tab and it'll be right in there, don't know about other OSes). It'll even work if IPv4 is broken (if you ran out of DHCP leases or whatever) because it almost always natively runs on IPv6 too.