Certificate warning
What you see: "Your connection is not private", "Warning: potential
security risk ahead", NET::ERR_CERT_AUTHORITY_INVALID, or a padlock with a
line through it, on an https:// address of the box.
Why
The box signs its own certificate; no public authority can issue one for a
.local name. Until your browser is told to trust that certificate, every
https:// page warns. Plain http://<address> never warns and is fine on
your own LAN; HTTPS matters for passkeys and for not sending the password in
the clear.
The fix: install the certificate once per computer
The wizard's first step shows the one-line installer; after setup the same files are still served by the box, LAN-only:
curl -fsSL http://<address>/setup/trust.sh | sh
irm http://<address>/setup/trust.ps1 | iex
The script adds one certificate to your user's browser stores and prints its
fingerprint; compare it with http://<address>/setup/state.json. Then
restart the browser and open https://<name>.local.
By hand: download http://<address>/setup/losos-ca.crt and add it as a
trusted certificate authority (Keychain Access on macOS, certmgr.msc →
Trusted Root Certification Authorities on Windows, the browser's own
certificate settings in Firefox, the phone's security settings).
Still warning after installing
- You opened
https://<address>. The certificate is for<name>.localonly; an IP address always warns. Use the name, or plainhttp://with the address. - Firefox on Linux keeps its own store per profile; the script covers every profile it finds, but a profile created later needs the script run again.
- The box was reinstalled or its name changed: it has a new certificate. Run the script again; the old entry does no harm.
- The certificate expired. It is valid for two years from the install; the box mints a new one when it runs out, and the script installs the new one.
- Chrome says the certificate is "not valid for this name" after a rename: same cause, same fix.
Should I just click through?
On your own LAN, for a box you installed yourself, clicking through once is not dangerous. But a browser that was told to ignore the warning will also ignore a real attacker on the same Wi-Fi, and passkeys will not be offered. Install the certificate instead; it takes one line.