Reply to post: Re: It's not "browsing" anymore..

Google Chrome update to label HTTP-only sites insecure within WEEKS

Anonymous Coward
Anonymous Coward

Re: It's not "browsing" anymore..

Certificates can contain URIs, DNS names, IPs, and other names in "subject alternative names" - which are those a browser (or any other well written application) should check - not only the "commonName".

So yes, you can issue a certificate to an IP address. Just, no well managed and sensible CA will ever release a certificate for LAN-reserved IPs.

If you run your internal PKI, and for some reason you want HTTPS to work with IPs as well (i.e. to reach some devices even if DNS is not working), you can issue certificates which contain also the IP - of course this is has some risks unless you manage IP allocations and certificates properly.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon