HTTPS cert for tplinkwifi.net needs tplinkwifi.net listed in the SAN

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

HTTPS cert for tplinkwifi.net needs tplinkwifi.net listed in the SAN

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
HTTPS cert for tplinkwifi.net needs tplinkwifi.net listed in the SAN
HTTPS cert for tplinkwifi.net needs tplinkwifi.net listed in the SAN
2023-12-25 02:10:44

This is related to BE9300 v1 firmware 1.0.4 Build 20231020 rel.53518(5553) since it's not in the model list, but probably affects several models.

 

The certificate that has been embedded with the firmware has a mismatched SAN DNS list that is going to throw security errors in every modern browser, and will not work correctly.  Security workarounds are not acceptable for devices not just marketed as routers, but also as security devices with subscriptions.

 

Ideally the DNS entry (tplinkwifi.net) and certificate should have functional default values, but at the price point of the BE9300 should also be user configurable and maintainable.

 

 

  0      
  0      
#1
Options
3 Reply
Re:HTTPS cert for tplinkwifi.net needs tplinkwifi.net listed in the SAN
2023-12-25 09:50:41

  @ndotb 

 

Hi, may I have a screenshot of the security errors you encountered when accessing the web interface via https?

Nice to Meet You in Our TP-Link Community. Check Out the Latest Posts: Archer GE550 - BE9300 Tri-Band Wi-Fi 7 Gaming Router EasyMesh Is Available When Wi-Fi Routers Work in AP Mode as A Controller. Archer BE550 New Software Enhances System Stability and Optimizes MLO Network Stability. TL-WA3001 Supports EasyMesh, Speed Limit, Guest Network in AP Mode and/or Multi-SSID Mode. If you found the post or response helpful, please click Helpful. If an answer solves your problem, click "Recommended Solution" so that others can benefit from it.
  0  
  0  
#2
Options
Re:HTTPS cert for tplinkwifi.net needs tplinkwifi.net listed in the SAN
2024-01-15 04:16:29

Ideally you should be able to use local ip address without constant attempts to redirect to tplinkwifi.net. DNS isn't very secure by design and opens unnecessary attack vector.

  0  
  0  
#3
Options
Re:HTTPS cert for tplinkwifi.net needs tplinkwifi.net listed in the SAN
2024-01-15 04:20:50
  0  
  0  
#4
Options