Hi @em286
There is a way to do that using Entware nginx-ssl package. While it is not a very straightforward one, it should work.
Install Entware
Run opkg update && opkg upgrade && opkg-install nginx-ssl in the Entware shell
Adjust /opt/etc/nginx/nginx.conf to proxy /auth and /rci/ requests to the firmware web server (see configuration below; replace "Home" segment address in it with 192.168.1.1)
Configure xxx.yyy.keenetic.name to proxy requests to "This Keenetic Device" + nginx-ssl port
This way X-NDM-Challenge and X-NDM-Realm headers will be preserved:
$ curl -i https://rci.dev-3811.keenetic.link/auth
HTTP/2 401
server: Web server
date: Mon, 29 Dec 2025 07:51:34 GMT
set-cookie: ... Path=/; SameSite=Strict; Max-Age=300
www-authenticate: x-ndw2-interactive ...
x-ndm-realm: Keenetic Hopper
x-ndm-challenge: BJ****
x-ndm-product: Hopper