× NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Orbi WiFi 7 RBE973
Reply

GS116Ev2 and HTTPS

JustSomeUser
Follower

GS116Ev2 and HTTPS

It appears that the latest Firmware for the GS116Ev2 does not support HTTPS. Are there any plans to add support in newer firmware release, particularly TLS1.2 or up? Since browsers are moving towards blocking weak or unencrypted communication, this would make the web interface inaccessible.

Apart from the browsers it's unadvisable to send a password over an unencrypted connection.

 

An alternative (not preferred) solution would be the possibility to restrict management access to a tagged vlan or particular switchport. This doesn't appear to be possible at this moment.

Model: GS116Ev2|ProSafe Plus 16 ports gigabits switch
Message 1 of 2

Accepted Solutions
schumaku
Guru

Re: GS116Ev2 and HTTPS


@JustSomeUser wrote:

It appears that the latest Firmware for the GS116Ev2 does not support HTTPS. Are there any plans to add support in newer firmware release, particularly TLS1.2 or up? Since browsers are moving towards blocking weak or unencrypted communication, this would make the web interface inaccessible.


Asked many times. There is no https available on any tiny micro-controllers in place to configure the switch core in this product line.

 

The browser makers are very progressive in blocking old "secure" https variants for good reasons - especially when it goes out to the Internet. Doubt plain http will be blocked soon. 

 

The real problem is getting a workable certificate to embedded devices in environments without local DNS, without own domains, ... all these security messages and warnings of insecure / untrusted / whatever are much more scarier for the average Joe.

 


@JustSomeUser wrote:

Apart from the browsers it's unadvisable to send a password over an unencrypted connection.


True. However, who does listen on your small home network or has physical access to your SOHO network?

 


@JustSomeUser wrote:

An alternative (not preferred) solution would be the possibility to restrict management access to a tagged vlan or particular switchport. This doesn't appear to be possible at this moment.


Here again, most Smart Managed Plus switches don't support a real management VLAN.

 

View solution in original post

Message 2 of 2

All Replies
schumaku
Guru

Re: GS116Ev2 and HTTPS


@JustSomeUser wrote:

It appears that the latest Firmware for the GS116Ev2 does not support HTTPS. Are there any plans to add support in newer firmware release, particularly TLS1.2 or up? Since browsers are moving towards blocking weak or unencrypted communication, this would make the web interface inaccessible.


Asked many times. There is no https available on any tiny micro-controllers in place to configure the switch core in this product line.

 

The browser makers are very progressive in blocking old "secure" https variants for good reasons - especially when it goes out to the Internet. Doubt plain http will be blocked soon. 

 

The real problem is getting a workable certificate to embedded devices in environments without local DNS, without own domains, ... all these security messages and warnings of insecure / untrusted / whatever are much more scarier for the average Joe.

 


@JustSomeUser wrote:

Apart from the browsers it's unadvisable to send a password over an unencrypted connection.


True. However, who does listen on your small home network or has physical access to your SOHO network?

 


@JustSomeUser wrote:

An alternative (not preferred) solution would be the possibility to restrict management access to a tagged vlan or particular switchport. This doesn't appear to be possible at this moment.


Here again, most Smart Managed Plus switches don't support a real management VLAN.

 

Message 2 of 2
Top Contributors
Discussion stats
  • 1 reply
  • 1038 views
  • 1 kudo
  • 2 in conversation
Announcements