Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. I currently run an acme server with a self signed root cert for internally hosted services on .home.arpa.

I currently run an acme server with a self signed root cert for internally hosted services on .home.arpa.

Scheduled Pinned Locked Moved Uncategorized
11 Posts 4 Posters 21 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • fallenhitokiri@social.screamingatmyscreen.comF fallenhitokiri@social.screamingatmyscreen.com

    I currently run an acme server with a self signed root cert for internally hosted services on .home.arpa. Works well enough most of the time, except when it doesn’t.

    I might just transition to *.hq.somedomain.tld and use Caddy’s DNS based verification for a wildcard cert or two.

    Might be a bit painful to change. At least it’ll be time consuming. And someone will explain me what a horrible idea it is to use a public domain and DNS for a private network.

    pfr@mastodon.bsd.cafeP This user is from outside of this forum
    pfr@mastodon.bsd.cafeP This user is from outside of this forum
    pfr@mastodon.bsd.cafe
    wrote last edited by
    #2

    @fallenhitokiri have your considered using #tailscale ?

    fallenhitokiri@social.screamingatmyscreen.comF 1 Reply Last reply
    0
    • fallenhitokiri@social.screamingatmyscreen.comF fallenhitokiri@social.screamingatmyscreen.com

      I currently run an acme server with a self signed root cert for internally hosted services on .home.arpa. Works well enough most of the time, except when it doesn’t.

      I might just transition to *.hq.somedomain.tld and use Caddy’s DNS based verification for a wildcard cert or two.

      Might be a bit painful to change. At least it’ll be time consuming. And someone will explain me what a horrible idea it is to use a public domain and DNS for a private network.

      ttk@ruhr.socialT This user is from outside of this forum
      ttk@ruhr.socialT This user is from outside of this forum
      ttk@ruhr.social
      wrote last edited by
      #3

      @fallenhitokiri So, i am using a public domain and DNS for my tailnet. Because of LE ACME. Since its my homelab net, it doesnt matter that DNS is public 😄

      fallenhitokiri@social.screamingatmyscreen.comF 1 Reply Last reply
      0
      • fallenhitokiri@social.screamingatmyscreen.comF fallenhitokiri@social.screamingatmyscreen.com

        I currently run an acme server with a self signed root cert for internally hosted services on .home.arpa. Works well enough most of the time, except when it doesn’t.

        I might just transition to *.hq.somedomain.tld and use Caddy’s DNS based verification for a wildcard cert or two.

        Might be a bit painful to change. At least it’ll be time consuming. And someone will explain me what a horrible idea it is to use a public domain and DNS for a private network.

        janantos@f.czJ This user is from outside of this forum
        janantos@f.czJ This user is from outside of this forum
        janantos@f.cz
        wrote last edited by
        #4

        @fallenhitokiri tbh. I do believe it is not that bad idea. Makes many things so much easier, I am doing the same, I had enough to deal with certificate trust cross several tools, browsers. And also I am using selfhosted DNS-over-HTTP and DNS-over-TLS and there you are literally done with self-signed certs. So you either pay hundreds of dollars for corporate cert yearly or max 5 usd for vps monthly with caddy. In fact I have my own domain and for this home infrastructure I am using 3rd level domain. Easy peasy, job done. Obviously plus domain cost about 10 euro.

        fallenhitokiri@social.screamingatmyscreen.comF 1 Reply Last reply
        0
        • pfr@mastodon.bsd.cafeP pfr@mastodon.bsd.cafe

          @fallenhitokiri have your considered using #tailscale ?

          fallenhitokiri@social.screamingatmyscreen.comF This user is from outside of this forum
          fallenhitokiri@social.screamingatmyscreen.comF This user is from outside of this forum
          fallenhitokiri@social.screamingatmyscreen.com
          wrote last edited by
          #5

          @pfr no. I don’t need most of their features and I don’t fancy running always on VPN for what’s a simple network setup.

          1 Reply Last reply
          0
          • janantos@f.czJ janantos@f.cz

            @fallenhitokiri tbh. I do believe it is not that bad idea. Makes many things so much easier, I am doing the same, I had enough to deal with certificate trust cross several tools, browsers. And also I am using selfhosted DNS-over-HTTP and DNS-over-TLS and there you are literally done with self-signed certs. So you either pay hundreds of dollars for corporate cert yearly or max 5 usd for vps monthly with caddy. In fact I have my own domain and for this home infrastructure I am using 3rd level domain. Easy peasy, job done. Obviously plus domain cost about 10 euro.

            fallenhitokiri@social.screamingatmyscreen.comF This user is from outside of this forum
            fallenhitokiri@social.screamingatmyscreen.comF This user is from outside of this forum
            fallenhitokiri@social.screamingatmyscreen.com
            wrote last edited by
            #6

            @janantos mostly thr same here 🙂 except I likely won’t bring in a VPS.

            Also optimist price for a SSL cert - I had the pleasure to buy an EV cert for signing Microsoft binaries and I never felt so dirty the last 20 years. (Plus the HSM… *sigh)

            janantos@f.czJ 2 Replies Last reply
            0
            • ttk@ruhr.socialT ttk@ruhr.social

              @fallenhitokiri So, i am using a public domain and DNS for my tailnet. Because of LE ACME. Since its my homelab net, it doesnt matter that DNS is public 😄

              fallenhitokiri@social.screamingatmyscreen.comF This user is from outside of this forum
              fallenhitokiri@social.screamingatmyscreen.comF This user is from outside of this forum
              fallenhitokiri@social.screamingatmyscreen.com
              wrote last edited by
              #7

              @ttk ich bin eher nicht so auf dem Tailscale Hype-Zug und mach Netzwerk und vpn wie meine graubärtigen Mentoren es mich gelehrt haben

              1 Reply Last reply
              0
              • fallenhitokiri@social.screamingatmyscreen.comF fallenhitokiri@social.screamingatmyscreen.com

                @janantos mostly thr same here 🙂 except I likely won’t bring in a VPS.

                Also optimist price for a SSL cert - I had the pleasure to buy an EV cert for signing Microsoft binaries and I never felt so dirty the last 20 years. (Plus the HSM… *sigh)

                janantos@f.czJ This user is from outside of this forum
                janantos@f.czJ This user is from outside of this forum
                janantos@f.cz
                wrote last edited by
                #8

                @fallenhitokiri for what you describe you might be ok with OV cert and there I would say it will ne few hundreds dollars

                fallenhitokiri@social.screamingatmyscreen.comF 1 Reply Last reply
                0
                • fallenhitokiri@social.screamingatmyscreen.comF fallenhitokiri@social.screamingatmyscreen.com

                  @janantos mostly thr same here 🙂 except I likely won’t bring in a VPS.

                  Also optimist price for a SSL cert - I had the pleasure to buy an EV cert for signing Microsoft binaries and I never felt so dirty the last 20 years. (Plus the HSM… *sigh)

                  janantos@f.czJ This user is from outside of this forum
                  janantos@f.czJ This user is from outside of this forum
                  janantos@f.cz
                  wrote last edited by
                  #9

                  @fallenhitokiri I am using VPS because of DNS server, I am using my own DoH in iPhone to block several stuff (Adblock, tracking, etc)

                  1 Reply Last reply
                  0
                  • janantos@f.czJ janantos@f.cz

                    @fallenhitokiri for what you describe you might be ok with OV cert and there I would say it will ne few hundreds dollars

                    fallenhitokiri@social.screamingatmyscreen.comF This user is from outside of this forum
                    fallenhitokiri@social.screamingatmyscreen.comF This user is from outside of this forum
                    fallenhitokiri@social.screamingatmyscreen.com
                    wrote last edited by
                    #10

                    @janantos via my clients contact we have been told by MS that Windows Defender etc. still reacts less aggressive for EV certificates for brand new apps.

                    Since I’ll have to do this for our project soon I’m curious if this was just wrong and OVs work as well?

                    janantos@f.czJ 1 Reply Last reply
                    0
                    • fallenhitokiri@social.screamingatmyscreen.comF fallenhitokiri@social.screamingatmyscreen.com

                      @janantos via my clients contact we have been told by MS that Windows Defender etc. still reacts less aggressive for EV certificates for brand new apps.

                      Since I’ll have to do this for our project soon I’m curious if this was just wrong and OVs work as well?

                      janantos@f.czJ This user is from outside of this forum
                      janantos@f.czJ This user is from outside of this forum
                      janantos@f.cz
                      wrote last edited by
                      #11

                      @fallenhitokiri I believe sou can’t sign app with OV only cert. Sorry I missed sou are issuing cert for app signing. My fault.

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups