You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If you run a private certificate authority — step-ca, your router's, your own — you can already trust its root in your browser and get a green padlock on anything it issues. What you could not do, until firmware v2.33.0, was get your certificate onto the board without SSH: there was no endpoint for it, and no control in the interface.
Now there is: give the board a PEM certificate and key — on the Security tab, with tpi tls install --cert --key, or PUT /api/bmc/tls/certificate — and it validates that they match, that the certificate is valid now and that it names the board, installs them atomically and reloads TLS without a restart. Every key type the daemon serves is covered by a real-handshake test — RSA, P-256, P-384, P-521, Ed25519 — so what is offered is what is proven. tpi tls reset hands the board back to its own self-signed one.
It also fixes the serial console for good: a browser will not open a WebSocket to a certificate it does not trust, and clicking through the page's warning does not extend to that connection.
The key never reaches a log: this takes a JSON body on its own path rather than the legacy interface, which records every mutating query string.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
If you run a private certificate authority — step-ca, your router's, your own — you can already trust its root in your browser and get a green padlock on anything it issues. What you could not do, until firmware v2.33.0, was get your certificate onto the board without SSH: there was no endpoint for it, and no control in the interface.
Now there is: give the board a PEM certificate and key — on the Security tab, with
tpi tls install --cert --key, orPUT /api/bmc/tls/certificate— and it validates that they match, that the certificate is valid now and that it names the board, installs them atomically and reloads TLS without a restart. Every key type the daemon serves is covered by a real-handshake test — RSA, P-256, P-384, P-521, Ed25519 — so what is offered is what is proven.tpi tls resethands the board back to its own self-signed one.It also fixes the serial console for good: a browser will not open a WebSocket to a certificate it does not trust, and clicking through the page's warning does not extend to that connection.
The key never reaches a log: this takes a JSON body on its own path rather than the legacy interface, which records every mutating query string.
Asked for twice in the Discord on 2026-09-14 (@casey, @machinchose) — this thread is the place for what is still missing. The guide: https://turingpi.xyz/guides/your-own-certificate/ · what shipped: https://turingpi.xyz/news/v2.34.0/
Status: Shipped in v2.33.0All reactions