I'm about to remotely deploy 30 RouterOS 6.4X devices.
Some are Internet-facing while some are not.
I would like to manage them with WebFig and HTTPS, if possible, along with SSH.
Only a couple of Linux PCs (from sysadmin team) will ever need to access WebFig.
May I add, that I'm not familiar with PKI or certificate concepts: as a sysadmin, I use them when I have to but I don't have a deep understanding.
To enable an HTTPS with a RouterOS 6.48 machine, I followed instructions from [1].
1. Given the number of devices currently shipped with vendor self-signed certs, do you fear Chrome or FF or others to remove, one day, the capability to access "self-signed web sites" ?
2. What are the advantages and limitations of generating certs locally instead of uploading them from a dedicated cert-producing host ?
3. What are the dangers of using very long validity (10 yers) as opposed to renew cert very often (3 months) ?
4. What are the steps to renew self-signed certs ?
5. Beside HTTPS access, what are embedded certs commonly used for ?
[1] https://www.medo64.com/2016/11/enabling ... -mikrotik/
Best regards