so the solution to the warning is to make your offline IoT devices secure, but how do you actually do that? i have an IoT product that runs a web server and needs to be accessible by users when the internet connection isn't available. how do I enable HTTPS on it? (this is not a hypothetical. it's a problem i actually need to solve)
as far as i can tell, my options are:
- install a self-signed cert on the device and force my users to click through all the warnings chrome throws up about untrusted certs
- create my own CA cert and sign the cert with that, and convince the user to install my CA cert as a trusted cert (which is not possible on iOS)
- get a cert signed by a trusted authority, and get the user to add an entry to their /etc/hosts file that maps the domain the cert is valid for whatever address the device is assigned
- distrubute a native (electron?) app that interfaces with my device and trusts my cert, and disallow direct browser access.
- find some sketchy SSL issuer who is willing to issue certs for *.local domains and run an mDNS resolver on my device
- Use HTTP instead of HTTPS and the only downside is a little badge in the address bar saying "not secure"
I'd love to have HTTPS everywhere, but i honestly don't know how to make it happen.