Let's Encrypt!
Let's Encrypt!
Sure, you can get anything to work, but it WILL be a huge PITA.
Unless your cron script is doing some funky DNS altering, that is.
[1] https://github.com/go-acme/lego [2] https://go-acme.github.io/lego/dns/
I would totally be down with say, the US government issuing citizens with a DNS name under their ccTLD somewhere. Done your tax paperwork in reasonable time? Your name is guaranteed by law to keep working for another year. Maybe 1480219643.ny.citizen-names.us is ugly but it'd satisfy this problem for individuals. Maybe they could bolt on a checkbox, $50 extra to the IRS and you get to pick any as-yet unreserved legal name, or they have rules like for license plates.
No, it wouldn't, because that involves interacting with the public DNS hierarchy.
> you shouldn't need to buy a domain to do stuff locally on your own device [emphasis added]
There are also free dynamic dns providers that let you set txt records and get certificates. But of course you can't depend on one of those to last forever.
1. have the domain in question resolve to a server with a public IP
2. have that server generate the certs with any ACME client with HTTP challenge
3. have that server ship the certs to the actual server hosting the service via intranet
4. in the intranet, have the domain resolve to the actual server via /etc/hosts override
All of that is not that hard to set up even at scale with proper config management tools. Having said that, I don't actually use it for that many services myself. The most significant one is LDAPS.
I have a wildcard certificate for *.local.example.com (and local.example.com), and a local DNS server which resolves all the subdomains of local.example.com.
All local servers share the same certificate and it gets refreshed automatically every 2 months. local.example.com has a public NS entry to a custom nameserver which only exists so that letsencrypt can perform the DNS validation for that domain (and its subdomains).
This way I can use server-1.local.example.com, server-2.local.example.com, workstation-1.local.example.com internally with TLS.