Believe it or not, I’ve never made (self-signed?) certificates for a domain I do not own. LetsEncrypt makes it look easy. I’m not sure how to properly make the subdomains work. Here is what the internet told me so far:
Full disclosure: This is for testing purposes only. I put all my barely updated security risk devices on a separate VLAN that cannot communicate with my main network, except for a single container, so I still need to make that proxy/relay work. I can’t have an open allow_anonymous listener on my main network because I’m paranoidafraid careful.
You don’t really need to fake the cloud garden domain (and id advise against it anyway), the devices don’t do any verification either of the common name, the SANs or the chain of trust.
In other words, as long as the server has a non-expired certificate, it’ll most likely work.