5 ms·
That approach has been mentioned in the comments. Some problems with it are: If a certificate is valid beyond 825 days Chrome will not honor it. So if you gene
by actionowl 7y ago
That approach has been mentioned in the comments. Some problems with it are:
If a certificate is valid beyond 825 days Chrome will not honor it. So if you generate a key and cert at the factory for every device you run into the issue of the end-user getting a device with an expired cert.
If you generate a unique key and self-signed cert users will complain and call support about the "insecure" site warning.
Communicating upstream to a third party to get a cert won't work for all users (e.g. those that need to configure a static IP from their ISP.)
- fulafel 7y agoYou shouldn't plug something with more than 2 years of missing security updates to the internet anyway (or sell it). Reflash & restock time by then.