Hi — thanks for VaulTLS; it's a great fit for an internal CA for my homelab
What I'm trying to do. Some devices terminate TLS but can't run an ACME client and are commonly reached by address rather than by name — a UniFi gateway console, a NAS, a printer. I issue them a TLS server certificate from a VaulTLS CA and install it on the device. For the UniFi console that means cert_type: 1 with usage_limit: ["router.home.lan", "router.local"], uploaded through the console's own API.
The gap: there is no way to put an IP address in the SAN list. The console is reached at https://192.168.1.1, and TLS clients match the SAN against the address exactly, so without an IP SAN the certificate is useless there. As far as I can tell TLSCertificateBuilder::set_dns_san (backend/src/certs/tls_cert.rs) is the only SAN builder — it calls SubjectAlternativeName::dns for every entry, and nothing parses an IpAddr. build_tls_cert (backend/src/api.rs) passes usage_limit straight into it, and the ACME path (issue_cert_from_csr) looks DNS-only as well. Verified on v1.3.0 and current main.
Would you add this feature or accept a patch? Something like: keep the API unchanged and
auto-detect per entry in the SAN builder — str::parse::<IpAddr>() routes to
SubjectAlternativeName::ip(...), everything else stays on .dns(...).
Hi — thanks for VaulTLS; it's a great fit for an internal CA for my homelab
What I'm trying to do. Some devices terminate TLS but can't run an ACME client and are commonly reached by address rather than by name — a UniFi gateway console, a NAS, a printer. I issue them a TLS server certificate from a VaulTLS CA and install it on the device. For the UniFi console that means
cert_type: 1withusage_limit: ["router.home.lan", "router.local"], uploaded through the console's own API.The gap: there is no way to put an IP address in the SAN list. The console is reached at
https://192.168.1.1, and TLS clients match the SAN against the address exactly, so without an IP SAN the certificate is useless there. As far as I can tellTLSCertificateBuilder::set_dns_san(backend/src/certs/tls_cert.rs) is the only SAN builder — it callsSubjectAlternativeName::dnsfor every entry, and nothing parses anIpAddr.build_tls_cert(backend/src/api.rs) passesusage_limitstraight into it, and the ACME path (issue_cert_from_csr) looks DNS-only as well. Verified on v1.3.0 and currentmain.Would you add this feature or accept a patch? Something like: keep the API unchanged and
auto-detect per entry in the SAN builder —
str::parse::<IpAddr>()routes toSubjectAlternativeName::ip(...), everything else stays on.dns(...).