Author Topic: Web Configuration page - Should I bother with TLS/SSL?  (Read 3806 times)

0 Members and 1 Guest are viewing this topic.

Offline djnz

  • Regular Contributor
  • *
  • Posts: 179
  • Country: 00
Re: Web Configuration page - Should I bother with TLS/SSL?
« Reply #25 on: March 22, 2018, 11:21:07 am »
One way to do this would be to setup your own Certificate Authority (CA) and use that to issue certs to your gadgets. The technician's laptop will need to have this CA cert added as a trusted CA (root authority). The advantage of this is that once you install the CA cert on the laptop, browsers will treat your gadget's certificates as proper ones issued by commercial CAs (not self-signed "snakeoil" ones), and you also get to decide cert lifetimes and save on cert charges.
 

Offline lty1993

  • Supporter
  • ****
  • Posts: 37
  • Country: us
    • LTY's Space
Re: Web Configuration page - Should I bother with TLS/SSL?
« Reply #26 on: March 22, 2018, 02:21:17 pm »
You can get a SSL certificate for bare IP from a trusted CA. However, you have to have that IP registered in your name from RIR (ARIN / RIPE / APNIC / AFRNIC / Etc).

I luckily had few IP subnets allocated from ARIN and RIPE, and I did actually get a bare IP certificate from a tursted CA few years ago.
 

Offline lty1993

  • Supporter
  • ****
  • Posts: 37
  • Country: us
    • LTY's Space
Re: Web Configuration page - Should I bother with TLS/SSL?
« Reply #27 on: March 22, 2018, 02:30:07 pm »
In my opinion, I will deploy all my products which will be used in remote locations with a dedicated network device, such as Cisco ISR 819, or Mikrotik mAP. All the security stuff (IPSec / VPN / Firewall) are handled by network devices, then I can safely use plain protocol on the actual product.
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf