3 ms·
The owner/operator of the router could do that to their own device, yes. The idea is that each router would get a certificate signed with a distinct subdomain
by CiPHPerCoder 7y ago
The owner/operator of the router could do that to their own device, yes.
The idea is that each router would get a certificate signed with a distinct subdomain unique to that router. So you still can't impersonate other devices. It wouldn't be a generic domain or wildcard certificate.
The remote signer would furthermore suspend suspicious connections (i.e. from multiple public IP addresses).