Hserver Failure Notes: Authentication and Ingress · intermediate

Internal CA Trust Is an Operator Onboarding Problem

A valid internal TLS certificate is still unusable on a new operator device until its trust root is installed correctly.

Current. Current engineering note based on recent hserver deployment, debugging, recovery, and production-hardening work in September 2026.

The Operations and OTA dashboards used Caddy internal CAs. New operator devices could reach the server but still encounter browser trust errors because the private roots were not part of the workstation trust store. Server-side certificate correctness and client-side trust bootstrap are two halves of the same TLS deployment. Production access documentation initially emphasized the server more than the operator onboarding path.

The deployment exports and fingerprints the public CA roots and the LAN bootstrap page serves only canonical dashboard links and those public certificates.

Treat a clean operator device as an acceptance environment. If a new authorized workstation cannot establish trust from documented steps, the TLS deployment is not operationally complete. Private PKI requires lifecycle management for trust anchors, not only leaf certificates. Distribution, fingerprint verification and revocation expectations belong in the runbook. The concrete hserver evidence is commit 1417d4b, so this note is tied to an actual production change rather than a hypothetical failure.

Quick navigationEsc