Skip to main content
DigiCert, Sectigo and GeoTrust SSL certificates
+90 850 259 76 06 WhatsApp Support Become a Reseller
SSL Certificates
Brands
Code Signing LEI Code
Tools
Support Contact WhatsApp Cart
Language
Currency
Get an SSL Certificate
SSL Certificate Types

What Is an IP SSL Certificate? How to Get SSL for an IP Address and Who Needs It

A service reached directly by IP address, with no domain name, can still be protected with HTTPS. What an IP SSL certificate is, which IP addresses qualify, how validation works and what to do about 192.168.x.x addresses on a local network.

5 min read

SSL certificates are usually associated with domain names, but not every service is published under one. If you connect to an admin panel, an API or a device directly at an address like https://203.0.113.10, the way to remove the browser’s "your connection is not private" warning is an IP SSL certificate: a certificate signed by a public certificate authority that contains the IP address instead of a domain name.

How does an IP SSL certificate work?

The browser compares the address it connected to with the entries in the certificate’s Subject Alternative Name (SAN) field. In a domain certificate those entries are domain names; in an IP certificate the IP address is listed as an entry of the IP address type. If the IP in the address bar matches the IP in the certificate exactly, the connection is treated as secure. Encryption strength and protocol are the same as for domain certificates.

Which IP addresses qualify?

IP addressExampleCan a certificate be issued?
Public, static IPv4203.0.113.10Yes
Private network10.x.x.x, 172.16–31.x.x, 192.168.x.xNo
Loopback127.0.0.1No
Dynamic IPThe address your provider assigns per connectionNot suitable

Private addresses are used in millions of networks at once, so they belong to no one; public certificate authorities have not issued certificates for them since 2016. A dynamic IP passes to someone else on the next connection, so a certificate for it loses its meaning.

How is validation done?

The certificate authority needs to see that you control the IP address. The most common method is file-based validation: you place a small file supplied by the authority on the web server running at that IP, and the authority reads it directly over the IP. The server therefore has to be reachable from outside during validation. The DNS TXT record and domain email methods used for domain names do not apply to IP addresses.

Who uses it?

  • Services without a domain name: APIs, admin panels, monitoring and backup interfaces reached by IP.
  • Infrastructure services: DNS-over-HTTPS resolvers and similar network services that are advertised by IP address.
  • Devices and network hardware: firewalls, video recorders and server management cards administered over a public IP.
  • Alongside a domain: a certificate containing both, for servers reached by name and by IP.

I have a private IP address. What should I do?

You cannot get a public certificate for an address like 192.168.x.x, but there are two sound options:

  1. Use a domain name. Point a subdomain such as panel.yourcompany.com at the private IP and get the certificate for that name. If you validate the domain with a DNS record, the server does not need to be exposed to the internet.
  2. Run your own internal certificate authority. Distribute your own root certificate to company devices and issue certificates for internal addresses yourself. Only devices on which you installed the root will trust them.

Things to watch for

  • Revoke the certificate when you give up the IP. When you release an IP from a cloud provider it is assigned to someone else; keeping a valid certificate for it is a risk.
  • There is no wildcard. You cannot cover an IP range with one entry; each address is listed separately.
  • Ask about IPv6 support first. The standard supports IPv6 addresses, but not every product does.
  • The same lifetime rules apply. IP certificates are also issued for at most 200 days; plan your renewals.

Is there a free option?

Let’s Encrypt issued its first IP address certificate in 2025. These certificates are only available as short-lived certificates of about six days and require full automation over ACME. For a device where you cannot set up automation, or when you want a longer-lived certificate with a warranty, paid IP certificates are the better fit.

IP SSL certificates at DATASSL

GoGetSSL Public IP SAN is a domain-validated certificate for public IP addresses: 2 addresses are included, it can be extended to 250, and there is no limit on the number of servers. You reissue it free of charge from your panel for the whole service period. The certificate decoder shows which addresses a certificate you hold covers.

In short

  • An IP SSL certificate protects a public, static IP address instead of a domain name.
  • Public certificates are not issued for private addresses (10.x, 172.16–31.x, 192.168.x).
  • Validation uses a file published on the IP; the server must be reachable from outside at that moment.
  • For private addresses, use a domain name with DNS validation or your own internal certificate authority.
Share this post
Ali Yiğit
Yazar

Ali Yiğit

Recommended SSL Certificates

All Products
DV GoGetSSL

GoGetSSL Public IP SAN

Protect your public IP addresses with the GoGetSSL IP SSL Certificate. 2 SANs included; expandable u

$20.00 /yr
Details
OV GoGetSSL

GoGetSSL BusinessTrust

Validate your business with GoGetSSL BusinessTrust SSL. $250,000 warranty, free dynamic site seal, v

$90.00 /yr
Details
EV GoGetSSL

GoGetSSL BusinessTrust EV

Get the most comprehensive identity validation with GoGetSSL BusinessTrust EV. $1,000,000 warranty,

$140.00 /yr
Details

Yorumlar

No comments yet. Be the first to comment!

Yorum Yaz