The browser viewer in the current Guardian Eye WebCamera beta does not use a URL such as https://192.168.1.42. Each installation gets its own name:
camera.<installation-id>.guardian-eye.local
The app publishes that name over mDNS and shows the complete viewer URL. The address can change when the phone reconnects to Wi-Fi, but the name and the certificate do not have to change with it.
The certificate setup has two parts. The phone creates a small certificate authority for this installation, then uses it to sign the certificate served by the viewer. The authority certificate can be exported from the app as a .cer file and installed on the computer that will open the viewer. The private keys never leave the phone; they remain in Keychain on iOS or AndroidKeyStore on Android.
This authority is deliberately narrow. It is constrained to the camera's exact .local name. It cannot issue a valid certificate for an IP address, a wildcard, another camera or a child name below its own name. Trusting it is therefore different from installing an unrestricted local CA.
The server certificate lasts 90 days and is replaced before it expires. That replacement does not require reinstalling the authority certificate because the new server certificate is signed by the same authority. The authority itself lasts up to two years. Resetting the TLS identity, or replacing the authority when it reaches the end of its lifetime, requires installing the newly exported certificate on viewer machines.
There is one platform difference after reinstalling the app. iOS keeps this identity in Keychain, so a normal uninstall and reinstall retains it. Android stores the installation identifier with the app and the keys in AndroidKeyStore, so uninstalling the app creates a new camera name and a new authority when it is installed again.
Opening the numeric IP address is not equivalent to opening the URL shown by the app: the certificate contains the canonical DNS name, not the current IP. If the browser reports a name or trust error, check that the exported authority is installed and that the viewer was opened using the exact .local URL displayed by WebCamera.
For beta testing, the useful cases are Wi-Fi reconnects, DHCP address changes, browser restarts and opening the same camera from more than one computer. Please include the phone OS, desktop OS and browser when reporting a certificate or name-resolution failure.
Source: r/GuardianEyeApps · by /u/sullivan-01