hermes gateway setup now asks 'Set up TLS now?' when IRIS_HTTP_CERT is not in .env (default No, Yes for an all-interfaces bind). Accepting generates a 10-year RSA-2048 self-signed cert with SANs (advertised LAN IP, hostname, loopback) under ~/.hermes/iris/ via hermes' existing cryptography dependency, saves IRIS_HTTP_CERT/IRIS_HTTP_KEY, and prints the SHA-256 fingerprint in openssl format for the app's confirm-and-pin dialog. The pairing URL/QR printed afterwards already advertise https. - key created 0600 from the start (no umask window) - save_env_value inside the best-effort guard (unwritable .env warns) - leftover cert without env var -> overwrite confirmation (protects the app's pinned fingerprint) - bind wildcards (0.0.0.0 / ::) never become SANs; :: gets the same default-Yes as 0.0.0.0 (pairing._unroutable parity) Tests: 5 new (cert generation incl. openssl fingerprint cross-check, accept/decline, no re-prompt, default-follows-bind, overwrite prompt). Docs: install.md Part 2 table + Part 4 Option B.