Names and TLS
Get a host name and HTTPS with or without a domain — mDNS, sslip.io / nip.io, your DNS, Let's Encrypt
Browsers, the native apps, passkeys and devices all need a host name that resolves to the server, and a certificate that carries it. Devices pin the certificate authority in their firmware, so pick the name before flashing them.
--domain | Example | Resolution | TLS | When |
|---|---|---|---|---|
| (default) | pnex.local | mDNS on the LAN | local CA | Raspberry Pi or Linux on a home or lab LAN |
sslip / nip | pnex-203-0-113-7.sslip.io | public wildcard DNS | Let's Encrypt (--tls cloud) | public VM without a domain name |
| your name | pnex.example.com | your DNS | Let's Encrypt (--tls cloud) or local CA | production, public access |
| an IP | 192.168.1.20 | none | local CA | last resort: passkeys are unavailable |
Wildcard DNS: sslip.io and nip.io
sslip.io and nip.io are free DNS services that answer with the IP address written in the name:
pnex-203-0-113-7.sslip.io → 203.0.113.7
pnex-203-0-113-7.nip.io → 203.0.113.7Their point is Let's Encrypt without DNS: a public VM named this way gets a certificate that every browser, app and device already trusts — no certificate authority to import anywhere.
curl -fsSL https://raw.githubusercontent.com/Pnex/pnex-deploy/main/install.sh \
| sudo bash -s -- --domain sslip --ip 203.0.113.7 --tls cloud \
--acme-email [email protected] --admin-user [email protected]--domain sslip (or nip) builds the name from the server's address; --ip
gives the public address when the VM only sees a private one behind the
provider's NAT. The installer uses the dashed form: the name stays a single
label, which certificates handle best.
With a private IP, a sslip.io name still works, with the local CA: you
import the CA as with .local. The only gain over a bare IP is a real host
name where mDNS fails (WSL, Android before 12, DNS-over-HTTPS browsers),
which keeps passkeys usable. That is why the installer uses it by default on
WSL.
Things to know:
- Clients and devices need internet DNS. A fully offline network needs mDNS or its own DNS server.
- Some routers drop public names resolving to private addresses (DNS rebinding
protection): allow-list
sslip.io/nip.ioin the router, or use another resolver. - The name contains the IP: give the server a DHCP reservation. After an
address change, re-run the installer with
--domain sslipand re-flash the devices. - To depend on no third party, delegate a subdomain of your own zone to a
self-hosted sslip.io DNS server, or create a wildcard record
(
*.lab.example.com) pointing at the server.
Local certificate authority
In local mode the installer creates a root CA once (10 years) and renews the
server certificate automatically. Each client trusts the CA once; it is served
at https://<server>/api/v1/meta/ca and shown in the web app under
Profile → About. Back it up: pnexctl backup includes it, and devices must be
re-flashed if it is lost.
Let's Encrypt
--tls cloud replaces the local CA by Let's Encrypt (HTTP-01 challenge,
renewal every 12 hours). It needs a public name and ports 80 and 443 reachable
from the internet. Devices trust the Let's Encrypt root (ISRG Root X1).

