logoalt Hacker News

progbitstoday at 5:53 PM2 repliesview on HN

I mean if it's not routable how do you want to prove ownership in a way nobody else can? Just make a domain name.


Replies

alibarbertoday at 6:04 PM

Also I don't see the point of what TLS is supposed to solve here? If you and I (and everyone else) can legitimately get a certificate for 10.0.0.1, then what are you proving exactly over using a self-signed cert?

There would be no way of determining that I can connecting to my-organisation's 10.0.0.1 and not bad-org's 10.0.0.1.

show 3 replies
arianvanptoday at 7:30 PM

For ipv6 proof of ownership can easily be done with an outbound connection instead. And would work great for provisioning certs for internal only services.