Skip to content

TLS server certificates: support IP addresses in SANs #251

Description

@strass

Hi — thanks for VaulTLS; it's a great fit for an internal CA for my homelab

What I'm trying to do. Some devices terminate TLS but can't run an ACME client and are commonly reached by address rather than by name — a UniFi gateway console, a NAS, a printer. I issue them a TLS server certificate from a VaulTLS CA and install it on the device. For the UniFi console that means cert_type: 1 with usage_limit: ["router.home.lan", "router.local"], uploaded through the console's own API.

The gap: there is no way to put an IP address in the SAN list. The console is reached at https://192.168.1.1, and TLS clients match the SAN against the address exactly, so without an IP SAN the certificate is useless there. As far as I can tell TLSCertificateBuilder::set_dns_san (backend/src/certs/tls_cert.rs) is the only SAN builder — it calls SubjectAlternativeName::dns for every entry, and nothing parses an IpAddr. build_tls_cert (backend/src/api.rs) passes usage_limit straight into it, and the ACME path (issue_cert_from_csr) looks DNS-only as well. Verified on v1.3.0 and current main.

Would you add this feature or accept a patch? Something like: keep the API unchanged and
auto-detect per entry in the SAN builder — str::parse::<IpAddr>() routes to
SubjectAlternativeName::ip(...), everything else stays on .dns(...).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions