WebFig over HTTPS in one click (v0.32.0)
#234: the "Unencrypted WebFig (www) is enabled" finding gets a Switch to
HTTPS button on a device's Security tab, and the same finding under
Common Findings on the Security page offers Switch all, one device at a
time. The switch keeps a working certificate already on www-ssl, else
shares api-ssl's, else creates and signs the self-signed mtm-api-ssl as
the API-SSL switch does; enables www-ssl on its existing port with www's
allowed addresses if it has none; and turns plain www off only once the
manager has seen WebFig answer over HTTPS. If it doesn't answer, www is
left on and the reason shown.
A new finding, "HTTPS WebFig (www-ssl) has no certificate", covers www-ssl
enabled without one, which can't complete an HTTPS handshake; the same
button fixes it.
Tested on a wAP ax (www on, www-ssl off; works alongside RouterOS 7.24's
reverse-proxy service on 443), a CRS309 (www-ssl on with no certificate),
and the failure path (www-ssl unreachable: www kept on).
Docs: security.md (WebFig over HTTPS).
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Container images (published once CI passes):
ghcr.io/2gt-media-group-llc/mikrotik-manager-backend:0.32.0-betaghcr.io/2gt-media-group-llc/mikrotik-manager-nginx:0.32.0-beta
Documentation: https://2gt-media-group-llc.github.io/mikrotik-manager/