<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[This is literally &quot;go fuck yourself&quot; advice.]]></title><description><![CDATA[<p class="quote-inline">RE: <a href="https://mastodon.transneptune.net/@owen/116541558564007666" rel="nofollow noopener"><span>https://</span><span>mastodon.transneptune.net/@owe</span><span>n/116541558564007666</span></a></p><p>This is literally "go fuck yourself" advice.</p>]]></description><link>https://board.circlewithadot.net/topic/afa337b6-b5e9-4bb4-bcbf-d8203953f3d2/this-is-literally-go-fuck-yourself-advice.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 04:33:06 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/afa337b6-b5e9-4bb4-bcbf-d8203953f3d2.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 08 May 2026 23:41:26 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Sat, 09 May 2026 16:40:27 GMT]]></title><description><![CDATA[<p><span><a href="/user/petrillic%40hachyderm.io">@<span>petrillic</span></a></span> <span><a href="/user/ryanc%40infosec.exchange">@<span>ryanc</span></a></span> <span><a href="/user/viq%40social.hackerspace.pl">@<span>viq</span></a></span> oh. Oh, shit.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/c0dec0dec0de/statuses/116545606635091537</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/c0dec0dec0de/statuses/116545606635091537</guid><dc:creator><![CDATA[c0dec0dec0de@hachyderm.io]]></dc:creator><pubDate>Sat, 09 May 2026 16:40:27 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Sat, 09 May 2026 16:26:09 GMT]]></title><description><![CDATA[<p><span><a href="/user/ryanc%40infosec.exchange">@<span>ryanc</span></a></span> <span><a href="/user/viq%40social.hackerspace.pl">@<span>viq</span></a></span> somehow this never quite clicked this way before. This is a great description.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/petrillic/statuses/116545550389181003</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/petrillic/statuses/116545550389181003</guid><dc:creator><![CDATA[petrillic@hachyderm.io]]></dc:creator><pubDate>Sat, 09 May 2026 16:26:09 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Sat, 09 May 2026 10:29:46 GMT]]></title><description><![CDATA[<p><span><a href="/user/ryanc%40infosec.exchange">@<span>ryanc</span></a></span> <span><a href="/user/petrillic%40hachyderm.io">@<span>petrillic</span></a></span> ah, thank you.</p>]]></description><link>https://board.circlewithadot.net/post/https://social.hackerspace.pl/users/viq/statuses/116544149037415963</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.hackerspace.pl/users/viq/statuses/116544149037415963</guid><dc:creator><![CDATA[viq@social.hackerspace.pl]]></dc:creator><pubDate>Sat, 09 May 2026 10:29:46 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Sat, 09 May 2026 06:35:37 GMT]]></title><description><![CDATA[<p><span><a href="/user/glyph%40mastodon.social">@<span>glyph</span></a></span> <span><a href="/user/keithzg%40fediverse.keithzg.ca">@<span>keithzg</span></a></span> <span><a href="/user/petrillic%40hachyderm.io">@<span>petrillic</span></a></span> <span><a href="/user/ryanc%40infosec.exchange">@<span>ryanc</span></a></span> this feels like the words of someone who dumped his ex after finding out she was literally a demon from hell... every so often he thinks of the amazing sex and is halfway to dialling her number before he remembers the claw marks, the ichor, and the creeping, gibbering madness</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/http_error_418/statuses/116543228301547756</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/http_error_418/statuses/116543228301547756</guid><dc:creator><![CDATA[http_error_418@hachyderm.io]]></dc:creator><pubDate>Sat, 09 May 2026 06:35:37 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Sat, 09 May 2026 06:25:10 GMT]]></title><description><![CDATA[<p><span><a href="/user/viq%40social.hackerspace.pl" rel="nofollow noopener">@<span>viq</span></a></span> <span><a href="/user/petrillic%40hachyderm.io" rel="nofollow noopener">@<span>petrillic</span></a></span>  since revocation doesn't work worth shit, they're basically bearer tokens with extra steps</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/ryanc/statuses/116543187240138477</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/ryanc/statuses/116543187240138477</guid><dc:creator><![CDATA[ryanc@infosec.exchange]]></dc:creator><pubDate>Sat, 09 May 2026 06:25:10 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Sat, 09 May 2026 04:35:14 GMT]]></title><description><![CDATA[<span><a href="/user/glyph%40mastodon.social" rel="ugc">@<span>glyph</span></a></span> <span><a href="/user/petrillic%40hachyderm.io" rel="ugc">@<span>petrillic</span></a></span> <span><a href="/user/ryanc%40infosec.exchange" rel="ugc">@<span>ryanc</span></a></span> It's been in operation a few years at work and It's Fine<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2122.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--tm" style="height:23px;width:auto;vertical-align:middle" title="™" alt="™" /> for our purposes but we're certainly not dynamically provisioning services or any such thing, it's *purely* for "make this host trusted for HTTPS purposes" and those hosts are few and static. And I definitely landed on just doing it with a few manual `openssl` calls and a convenience script or two after surveying the more fully-featured run-your-own-CA software options out there, laughing nervously, and then quickly shutting the door.]]></description><link>https://board.circlewithadot.net/post/https://fediverse.keithzg.ca/objects/2015cbdc-ef57-4f92-9132-cbac76581fa1</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fediverse.keithzg.ca/objects/2015cbdc-ef57-4f92-9132-cbac76581fa1</guid><dc:creator><![CDATA[keithzg@fediverse.keithzg.ca]]></dc:creator><pubDate>Sat, 09 May 2026 04:35:14 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Sat, 09 May 2026 03:16:14 GMT]]></title><description><![CDATA[<p><span><a href="/user/petrillic%40hachyderm.io">@<span>petrillic</span></a></span> It may be a pain; but at least there are a variety of somewhat non-obvious ways to make it actively dangerous without noticing. What's not to like?</p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/fuzzyfuzzyfungus/statuses/116542444295894467</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/fuzzyfuzzyfungus/statuses/116542444295894467</guid><dc:creator><![CDATA[fuzzyfuzzyfungus@cyberplace.social]]></dc:creator><pubDate>Sat, 09 May 2026 03:16:14 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Sat, 09 May 2026 01:41:17 GMT]]></title><description><![CDATA[<p><span><a href="/user/keithzg%40fediverse.keithzg.ca">@<span>keithzg</span></a></span> <span><a href="/user/petrillic%40hachyderm.io">@<span>petrillic</span></a></span> <span><a href="/user/ryanc%40infosec.exchange">@<span>ryanc</span></a></span> citation: I once wrote a tool that made every user an mTLS CA in a complex dynamic trust mesh and in my darker moments I still think … maybe it could work …</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/glyph/statuses/116542070916720742</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/glyph/statuses/116542070916720742</guid><dc:creator><![CDATA[glyph@mastodon.social]]></dc:creator><pubDate>Sat, 09 May 2026 01:41:17 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Sat, 09 May 2026 00:43:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/keithzg%40fediverse.keithzg.ca">@<span>keithzg</span></a></span> <span><a href="/user/petrillic%40hachyderm.io">@<span>petrillic</span></a></span> <span><a href="/user/ryanc%40infosec.exchange">@<span>ryanc</span></a></span> yeah everybody who eventually goes through the “find out” phase initially feels like this about operating a CA <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f643.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--upside_down_face" style="height:23px;width:auto;vertical-align:middle" title="🙃" alt="🙃" /></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/glyph/statuses/116541842990110018</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/glyph/statuses/116541842990110018</guid><dc:creator><![CDATA[glyph@mastodon.social]]></dc:creator><pubDate>Sat, 09 May 2026 00:43:19 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Sat, 09 May 2026 00:38:51 GMT]]></title><description><![CDATA[<span><a href="/user/glyph%40mastodon.social" rel="ugc">@<span>glyph</span></a></span> <span><a href="/user/ryanc%40infosec.exchange" rel="ugc">@<span>ryanc</span></a></span> <span><a href="/user/petrillic%40hachyderm.io" rel="ugc">@<span>petrillic</span></a></span> I find running our own CA at my work easy enough, but the scale is verrrry small and frankly I'm probably skipping a lot of steps that "real" CAs wouldn't]]></description><link>https://board.circlewithadot.net/post/https://fediverse.keithzg.ca/objects/fe86201b-60e2-4cf3-b3ba-b7f5ea020da1</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fediverse.keithzg.ca/objects/fe86201b-60e2-4cf3-b3ba-b7f5ea020da1</guid><dc:creator><![CDATA[keithzg@fediverse.keithzg.ca]]></dc:creator><pubDate>Sat, 09 May 2026 00:38:51 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Sat, 09 May 2026 00:21:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/ryanc%40infosec.exchange">@<span>ryanc</span></a></span> <span><a href="/user/petrillic%40hachyderm.io">@<span>petrillic</span></a></span> as you mentioned in the replies, acme-dns for lan addresses is *almost* reasonable (I also do it, it’s… fine… I am sympathetic to the OP’s desire for more reasonable treatment of .local but I have unironically recommended it to people who have been more or less satisfied with it) but running your own CA is advice from people who have only daydreamed about operating PKI infrastructure.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/glyph/statuses/116541756507584381</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/glyph/statuses/116541756507584381</guid><dc:creator><![CDATA[glyph@mastodon.social]]></dc:creator><pubDate>Sat, 09 May 2026 00:21:19 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Sat, 09 May 2026 00:14:26 GMT]]></title><description><![CDATA[<p><span><a href="/user/ryanc%40infosec.exchange">@<span>ryanc</span></a></span> <span><a href="/user/petrillic%40hachyderm.io">@<span>petrillic</span></a></span> I clearly don't know enough. What are some of the reasons for "if you hate yourself"?</p>]]></description><link>https://board.circlewithadot.net/post/https://social.hackerspace.pl/users/viq/statuses/116541729431329505</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.hackerspace.pl/users/viq/statuses/116541729431329505</guid><dc:creator><![CDATA[viq@social.hackerspace.pl]]></dc:creator><pubDate>Sat, 09 May 2026 00:14:26 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Sat, 09 May 2026 00:02:40 GMT]]></title><description><![CDATA[<p><span><a href="/user/ryanc%40infosec.exchange">@<span>ryanc</span></a></span> yourself, and everyone who comes after you.</p><p>Whew <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /> Choices.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/petrillic/statuses/116541683181974449</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/petrillic/statuses/116541683181974449</guid><dc:creator><![CDATA[petrillic@hachyderm.io]]></dc:creator><pubDate>Sat, 09 May 2026 00:02:40 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Fri, 08 May 2026 23:56:34 GMT]]></title><description><![CDATA[<p><span><a href="/user/petrillic%40hachyderm.io" rel="nofollow noopener">@<span>petrillic</span></a></span> when I was interviewing for my current job, it was relevant, so I told the guy who was interviewing me "...and you could use mTLS, if you hate yourself", and from that point on we were just casually chatting.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/ryanc/statuses/116541659203547227</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/ryanc/statuses/116541659203547227</guid><dc:creator><![CDATA[ryanc@infosec.exchange]]></dc:creator><pubDate>Fri, 08 May 2026 23:56:34 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Fri, 08 May 2026 23:53:40 GMT]]></title><description><![CDATA[<p><span><a href="/user/ryanc%40infosec.exchange">@<span>ryanc</span></a></span> this is the kind way to view mTLS</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/petrillic/statuses/116541647778844206</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/petrillic/statuses/116541647778844206</guid><dc:creator><![CDATA[petrillic@hachyderm.io]]></dc:creator><pubDate>Fri, 08 May 2026 23:53:40 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Fri, 08 May 2026 23:51:37 GMT]]></title><description><![CDATA[<p><span><a href="/user/petrillic%40hachyderm.io" rel="nofollow noopener">@<span>petrillic</span></a></span> I ran a CA for my previous employer, I learned a lot, for example, fuck mTLS.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/ryanc/statuses/116541639741118719</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/ryanc/statuses/116541639741118719</guid><dc:creator><![CDATA[ryanc@infosec.exchange]]></dc:creator><pubDate>Fri, 08 May 2026 23:51:37 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Fri, 08 May 2026 23:47:11 GMT]]></title><description><![CDATA[<p><span><a href="/user/petrillic%40hachyderm.io">@<span>petrillic</span></a></span> It _deeply_ is. I ran a small CA for my own services for a while, and it was a constant thorn in my side. I can't imagine trying to persuade visitors to use it or trying to get some kid's Switch to accept those certs, nor would I want to leave them with the wreckage afterwards.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.transneptune.net/users/owen/statuses/116541622284120569</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.transneptune.net/users/owen/statuses/116541622284120569</guid><dc:creator><![CDATA[owen@mastodon.transneptune.net]]></dc:creator><pubDate>Fri, 08 May 2026 23:47:11 GMT</pubDate></item><item><title><![CDATA[Reply to This is literally &quot;go fuck yourself&quot; advice. on Fri, 08 May 2026 23:42:17 GMT]]></title><description><![CDATA[<p>I have, quite literally, written a bunch of code that (at least used to be) is part of a major commercial CA product.</p><p>You do not want to do this.</p><p>Unless you hate yourself. Deeply.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/petrillic/statuses/116541602990362757</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/petrillic/statuses/116541602990362757</guid><dc:creator><![CDATA[petrillic@hachyderm.io]]></dc:creator><pubDate>Fri, 08 May 2026 23:42:17 GMT</pubDate></item></channel></rss>