SSL certificates are usually associated with domain names, but not every service is published under one. If you connect to an admin panel, an API or a device directly at an address like https://203.0.113.10, the way to remove the browser’s "your connection is not private" warning is an IP SSL certificate: a certificate signed by a public certificate authority that contains the IP address instead of a domain name.
How does an IP SSL certificate work?
The browser compares the address it connected to with the entries in the certificate’s Subject Alternative Name (SAN) field. In a domain certificate those entries are domain names; in an IP certificate the IP address is listed as an entry of the IP address type. If the IP in the address bar matches the IP in the certificate exactly, the connection is treated as secure. Encryption strength and protocol are the same as for domain certificates.
Which IP addresses qualify?
| IP address | Example | Can a certificate be issued? |
|---|---|---|
| Public, static IPv4 | 203.0.113.10 | Yes |
| Private network | 10.x.x.x, 172.16–31.x.x, 192.168.x.x | No |
| Loopback | 127.0.0.1 | No |
| Dynamic IP | The address your provider assigns per connection | Not suitable |
Private addresses are used in millions of networks at once, so they belong to no one; public certificate authorities have not issued certificates for them since 2016. A dynamic IP passes to someone else on the next connection, so a certificate for it loses its meaning.
How is validation done?
The certificate authority needs to see that you control the IP address. The most common method is file-based validation: you place a small file supplied by the authority on the web server running at that IP, and the authority reads it directly over the IP. The server therefore has to be reachable from outside during validation. The DNS TXT record and domain email methods used for domain names do not apply to IP addresses.
Who uses it?
- Services without a domain name: APIs, admin panels, monitoring and backup interfaces reached by IP.
- Infrastructure services: DNS-over-HTTPS resolvers and similar network services that are advertised by IP address.
- Devices and network hardware: firewalls, video recorders and server management cards administered over a public IP.
- Alongside a domain: a certificate containing both, for servers reached by name and by IP.
I have a private IP address. What should I do?
You cannot get a public certificate for an address like 192.168.x.x, but there are two sound options:
- Use a domain name. Point a subdomain such as
panel.yourcompany.comat the private IP and get the certificate for that name. If you validate the domain with a DNS record, the server does not need to be exposed to the internet. - Run your own internal certificate authority. Distribute your own root certificate to company devices and issue certificates for internal addresses yourself. Only devices on which you installed the root will trust them.
Things to watch for
- Revoke the certificate when you give up the IP. When you release an IP from a cloud provider it is assigned to someone else; keeping a valid certificate for it is a risk.
- There is no wildcard. You cannot cover an IP range with one entry; each address is listed separately.
- Ask about IPv6 support first. The standard supports IPv6 addresses, but not every product does.
- The same lifetime rules apply. IP certificates are also issued for at most 200 days; plan your renewals.
Is there a free option?
Let’s Encrypt issued its first IP address certificate in 2025. These certificates are only available as short-lived certificates of about six days and require full automation over ACME. For a device where you cannot set up automation, or when you want a longer-lived certificate with a warranty, paid IP certificates are the better fit.
IP SSL certificates at DATASSL
GoGetSSL Public IP SAN is a domain-validated certificate for public IP addresses: 2 addresses are included, it can be extended to 250, and there is no limit on the number of servers. You reissue it free of charge from your panel for the whole service period. The certificate decoder shows which addresses a certificate you hold covers.
In short
- An IP SSL certificate protects a public, static IP address instead of a domain name.
- Public certificates are not issued for private addresses (10.x, 172.16–31.x, 192.168.x).
- Validation uses a file published on the IP; the server must be reachable from outside at that moment.
- For private addresses, use a domain name with DNS validation or your own internal certificate authority.

Yorumlar
No comments yet. Be the first to comment!
Yorum Yaz