[Settle] Deployment experience - public CA certs for LAN devices (devicessl)
Adam Raźniewski <adam.razniewski@adaraz.com> Fri, 25 September 2026 14:12 UTC
Received: by mx.ietf.org (Postfix) id 04DAD3F for <settle@ietf.org>; Fri, 25 Sep 2026 14:12:20 +0000 (UTC)
Received: by mail-lf2-x11.google.com with SMTP id 2adb3069b0e04-5b8ecca9f3fso283989e87.2 for <settle@ietf.org>; Fri, 25 Sep 2026 07:10:39 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1790345438; cv=none; d=google.com; s=arc-20260327; b=ItBLhCQD1qIR5hvksR4S0/zcHs+v7ibnp4gR4EdUaUm83gNAoJm1+RN2wVvNbiAArc NiY+PaPgItmWFN9Zw7M2OkACzj+cm2KX8ISa5KAwu1Ou2RbIgxWceFihwD6OGdwBjdIV MFfPHvM9r6ONWqtWdTjEz05M0IGM0/G4BFre3vYkGfo9FUA7GE/yQ1YeZtAaho8tp4dY 8mISSqEU0k4Ux1e+hJRLoHuzbWffFzNICVkQRh09NwYJ15fbtYnl7GYgtv9++QydSfZb xXnsR+gFuXxh5UBWafFFSsEw9tM5n9Fc/cCAP7t1BWnDAD80Citi6v5FBa1xb74SDcJj f5SQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:mime-version:dkim-signature; bh=CymTvYt1832XooM2Ffy3ocNZ3r50b4mdiqHFOX78kJw=; fh=B7xQDXQnCP+nTozgkf8H6RYwCTWYL6j5/JC4PHN9gd8=; b=XosR9jJ70CXvaw+p4r+YMj2YeF8SKlha4u4UsoprAWSitdXMA6WPhDTRW17qwDhImN 9JTuLDYlvfJHzv+4sPnd4BZ3VZ5jtAzVt5aKvVQKMgpCpDY4wtf1AoDkukO4z/2XT7+P P5NMOWRNfd/aSvdXK0spgJwXfYTN3o95I5OMLOIVSctEnWtHwsvTckzdvDtXHoRj1OFY bRf9S4YAyF0lbNbdXAi1D9hflcPetXQ7dWKZVyOgC65MwKgzfaGKCKRP9+kuBvb7BrEh yxEOmbpnYly06IHZFVs/h1LkzEfuDwZuPjV3Xdn14ktF3mpln6cE/N1AgVa+pvZoktPv SvpQ==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=adaraz.com; s=google; t=1790345438; x=1790950238; darn=ietf.org; h=content-type:to:subject:message-id:date:from:mime-version:from:to :cc:subject:date:message-id:reply-to:content-type; bh=CymTvYt1832XooM2Ffy3ocNZ3r50b4mdiqHFOX78kJw=; b=HYYTf6gm/U9SG7YGJLH5uICI/KPmLU+AKoVX3SOrDejZnxEIyHDiJG+xjI1RYMjRiM CHIMPfQeICzZo23N9HWNuH8e4Pry/GqICDC67uggngBO5o699O+9UvJ0i21SeOnyvpCq 1/IhPi5hOFS+zsz/MHvV9z58MYVWroVnOX+77vrDMfU9/2ACl8CHsYlRtrR4qe6MZFep j2dbulW1IGriKxUvWeBWwneWFg7zdy+/fYG3DI2pPgLyXlGkMO+BlQm9DBLWrCwP17eT PNU9ngy5ZSYYRKHGVr9lfEpKNwYfZ7R99gRkjiDOs8Vp7zsMDTPc4mZd7zk/4Y7IzdtV p4hg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790345438; x=1790950238; h=content-type:to:subject:message-id:date:from:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=CymTvYt1832XooM2Ffy3ocNZ3r50b4mdiqHFOX78kJw=; b=D9VwOJ3dcZYgPc3khaWg6Y9J5fqlCOyv/X8dRGgsoUGOdpEP89E670HLMuqbxHjMmb b277yIpaT8Se+lLovYSm8wFBur5UwFoJiA0Oi5iZEmDH2PzPl7XqT/i/jMNfJXBsS41E K+UBLQBtwHolffZOVQnNeHD/PsIY/X/ksxzd8gB6vXUHS7K9idfBN+qcopQiWbntd8Uw sraSmtZNllkM5eDbhw8gMf6EjFhPRe/R2sHwefa/WwV3h4yBaYyzeFurfCCfpJpvqGL1 oj7Ov5Vtpho+exRkQ9sAL/c0IjDcDGcnei1FHMElwuumiqSV/eAE2t90m94PkKdD+tTt m64Q==
X-Gm-Message-State: AFuF++lSCVZqDrcu/ZMORTWNZUebnP0+t+l9uU8usARE0VAyTThdmyzJ hn+/obgPUKpJ8kNkH1P8KK0+b5S7hBgmnAEmLfCwt1hqLWY6Is32cda6nYOlpQ0gD4tqLKonWAc LKenLW1v0cq/7LPab+TMgJKenWK90DvZKaqSx600ilXbmL0iwHsg1iDrOCzg9
X-Gm-Gg: AYBFou0LQyaWWEdXyPslJtdIacKnPW7jB96OI/s8qYFPCCIK5ZlQ3LckVAFENwG8EW4 ajsb26rvVxzc/9jvokOpf5DMgDgfGr4yjnSiXw5NqYVsGSfpohy7Hk3YzPYUbl55hxOvGJTbRgR tkAapEGoNnO99C1isUVoFVKaV6fJJdu1TI37STk7vUMIj997CUy52+J39oBnLJhIgKLkD2AnKAD dXNGF2yObEeX57ZJPvRmfw7bsGWXXZIIES3t8QzOFEtHJUG/Y793jXgo48OC/bDyj9RS/IEGkMc p8AlfD7rYiS1xTBAeOx9UxxQKMFOv3TjSI2hva//yiB+WWCvN3lyYZA=
X-Received: by 2002:a05:6512:688f:20b0:5b1:5ccf:5268 with SMTP id 2adb3069b0e04-5b8df06b4e4mr1414633e87.1.1790345437699; Fri, 25 Sep 2026 07:10:37 -0700 (PDT)
MIME-Version: 1.0
From: Adam Raźniewski <adam.razniewski@adaraz.com>
Date: Fri, 25 Sep 2026 16:10:25 +0200
X-Gm-Features: AclHuK-PYcE7t1Yl5wf-kzRgQJGgXiRWTLwr9dWSoqB5ldSqOKmXpuVVk3_b0mM
Message-ID: <CA+c7DyX9TqXBoD9+juTWnkXLVsxwDL83NE0TGH9dy2Ly+jZaKg@mail.gmail.com>
To: settle@ietf.org
Content-Type: multipart/alternative; boundary="000000000000d6ecbf065c4f4770"
Message-ID-Hash: G7TS7CWNKYXGOT5VIW23KWMVSWDFQEOX
X-Message-ID-Hash: G7TS7CWNKYXGOT5VIW23KWMVSWDFQEOX
X-MailFrom: adam.razniewski@adaraz.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.10
Precedence: list
Subject: [Settle] Deployment experience - public CA certs for LAN devices (devicessl)
List-Id: "SEcure access To Tls Local rEsources. To discuss non-PKI methods of identifying and authenticating to TLS endpoints in a local domain." <settle.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/settle/bNyNRSiqklrFkWlcPkJBhStHhAE>
List-Archive: <https://mailarchive.ietf.org/arch/browse/settle>
List-Help: <mailto:settle-request@ietf.org?subject=help>
List-Owner: <mailto:settle-owner@ietf.org>
List-Post: <mailto:settle@ietf.org>
List-Subscribe: <mailto:settle-join@ietf.org>
List-Unsubscribe: <mailto:settle-leave@ietf.org>
Hey all, I saw the call for volunteers for the problem statement in February, so maybe this insight will be useful. We are small Polish electronics manufacturer. We make time and attendance terminals and firmware for other companies, and also other devices. Our customers are restaurants, shops, small offices. No IT team, devices are self-installed. Honestly, from manufacturer side it's really strange that in 2026 this is still not solved. Every device on a LAN has a web panel, and there is still no normal way to serve it over HTTPS (without warnings). Sniffing a local network today is trivial, one cheap device or an infected laptop is enough, and passwords to the panel go in plain text or behind a self-signed cert that everyone clicks through. And we also have to comply with EN 18031-1, the harmonised standard for the EU Radio Equipment Directive (Delegated Regulation 2022/30, mandatory since August 2025). For a device with a web panel on a LAN this means: - SCM-1 (6.5.1): the device shall always use secure communication for security and network assets, e.g. panel passwords. Exceptions are only physically closed environments or a VPN - not a restaurant Wi-Fi. - SCM-2 (6.5.2): integrity and authenticity protection, i.e. against man-in-the-middle. The standard itself says the way the initial trust relationship is established is "crucial". - SCM-3 (6.5.3): confidentiality, so encryption. - CCK-3 (6.9.3): preinstalled keys must be practically unique per device, so no shared key or cert in the firmware. So "just use HTTP" is not an option anymore. Self-signed gives encryption but not authenticity, since users click through the warning. And "install your own CA" is not an option for a restaurant owner. There is simply no compliant option that normal people can use. And honestly, I suspect a lot of manufacturers don't really comply with EN 18031-1 not because they don't care, but because there is no practical way to do it. We built our own thing, to somehow WORKAROUND a problem. But from user perspective and user experience to be honest it's... You know the word (bad at least). a) every device has its own zone <device-id>.d.devicessl.com b) device generates its key itself, sends only CSR c) we do DNS-01 on our own DNS and get Let's Encrypt wildcard *.<device-id>. d.devicessl.com d) private IP is encoded in the name, e.g. 192-168-1-50.<device-id>. d.devicessl.com So it results in "green" padlock on 192-168-1-50.DEVICE_ID.d.devicessl.com It works, but with problems: 1. many routers block DNS answers with private IPs (rebinding protection), customer must add exception 2. needs internet, offline sites fall back to self-signed 3. no site isolation between devices - we applied to PSL and were declined (LAN only use case) - cookie issue 4. Cumbersome - nobody will remember it. Also, today we can't even properly use mDNS in the local network. Our devices announce themselves as e.g. rcp-a1b2c3d4.local, which is the most natural way to find a device on a LAN. But we can never open it over HTTPS with a valid cert, because no public CA will issue a certificate for .local. So the "nice" local name is exactly the one that can never be secure. A standard would *really* help. My dream is that user can have encrypted and authenticated connection on https://please-its-just-my-local-device.local And we, as manufacturers of local IoT devices, have a super easy way to achieve it. Happy to share more details if it's useful. Adam Raźniewski https://adaraz.com
- [Settle] Deployment experience - public CA certs … Adam Raźniewski
- [Settle] Re: Deployment experience - public CA ce… Michael Sweet