The non-profit certificate authority Let’s Encrypt, governed by the community and providing certificates free of charge to anyone who wishes, has announced the start of issuing free certificates for IP addresses. Unlike domain certificates, the validity period for IP address certificates will last for 30 and 6 days. This feature will enable secure encrypted access to hosts not only when using domain names, but also when accessing directly via the IP address.
Among the areas where secure access to a web server directly via IP addressis expected to be in demand are interactions with home devices, such as storage servers; initial setup or testing of new servers; establishing encrypted connections between backends in the internal infrastructure; creating informational placeholder pages by hosting providers that are displayed by default when accessing via IP; organizing access to services tied to IP addresses, such as 1.1.1.1 and 8.8.8.8; deploying personal servers where one does not want to spend money on domain registration; organizing access to DoH (DNS over HTTPS) servers directly via IP.
Currently, certificates for IP addresses are being generated in test mode and will be available for general use later this year, simultaneously with the ability to generate short-lived certificates for domains that last for 6 days. To request a short-lived certificate and an IP certificate, support for the extension of the protocol implementing profiles, as well as support for the 'shortlived' profile, is required in the ACME client. To verify ownership of the IP address, only the http-01 and tls-alpn-01 methods can be used (the dns-01 method is prohibited).
Source: opennet.ru
