3 ms·
An alternate solution to the same problem would be to streamline running your own local certificate authority. For example: if the local router was its own cert
by nbadg 6y ago
An alternate solution to the same problem would be to streamline running your own local certificate authority. For example: if the local router was its own certificate authority (that spoke ACME), and OSes and/or browsers were configured to check with the local gateway for their cert authority. You could add the Name Constraints exception and restrict it to local-only (reserved) TLDs.
- floatingatoll 6y agoI don’t consider this approach to be possible to operate usefully at scale with completely non-technical users, as they aren’t interested in operating a minor bureaucracy for their thermostat to work. I am capable of operating my own CA out of my home in a matter of minutes in order to solve this problem, yet even I consider it a waste of my time to do so. In-home transport encryption should not demand a burden from the user. To quote Brazil: “Listen, this whole system of yours could be on fire and I couldn't even turn on the kitchen tap without filling out a twenty-seven B stroke six.”