New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
Let's Encrypt : We Issued Our First IP Address Certificate !
Since 1st July 2025, Let's Encrypt can issue IP Address Certificate !
To have your first IP CERTIFICATE go to staging
A good usage is Securing remote access IP like device, VPS host, RDP, ...
So good luck LETSENCRYPT !
Source LetsEncrypt.org


Comments
Great news
On another hand malware C&C's will also celebrate.
Make use of it while it lasts 🤣
can i wildcard 0.0.0.0/0
There are certificates everywhere today. How would they do more damage with an SSL Letsencrypt certificate? I am curious to see your/the solution.
I suggest to try to acquire the best for you 255.255.255.255/32
Now they need domain to be purchased and active. IP, especially ipv6 is unmetered resource for malice. But that’s just fud. Safely ignore. Doomer must doom.
They can just dispose of addresses after use like they don't use hacked servers for c2?
Why would they use https? Simply useless and makes their stuff more easily detectable (see: cert transparency).
Wait, so encryption in this case is bad?
They can just pin a certificate which doesn't need to be publicly trusted.
So that it isn't easily picked off with a basic DPI firewall.
In case anyone managed to create certs for IPs, which ACME client or whatever did you use?
Why not just wrap in a custom encryption algo with http
Look here https://letsencrypt.org/docs/client-options/
My providers generate for me, otherwise i order year ssl certs.
https://github.com/dehydrated-io/dehydrated supports these new certificates
download the zip of the master branch, create "config" file
and run
./dehydrated -c -d ip:YOURIPyour cert will be in the certs folder
they are still in development and aren't trusted yet
source: https://github.com/dehydrated-io/dehydrated/issues/783#issuecomment-3031888207
good news
Easier detection
Top comment of this topic !