throwaway2037 3 days ago

Real question: What is the correct way to handle certs on embedded devices? I never thought about it before I read this comment.

1
steve_gh 3 days ago

There are many embedded devices for which TLS is simply not feasible. For remote sensing, when you are relying on battery power and need to maximise device battery life, then the power budget is critical. Telemetry is the biggest drain on the power budget, so anything that means spending more time with the RF system powered up should be avoided. TLS falls into this category.

dcow 3 days ago

Yes, but the question is about devices that can reasonably run TLS.

The answer is local acme with your router issuing certs for your ULA prefix or “home zone” domain.

thayne 2 days ago

> The answer is local acme with your router issuing certs for your ULA prefix or “home zone” domain.

That would be nice. But most people don't have a router running an ACME server.

dcow 2 days ago

It should become a thing