Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. This is literally "go fuck yourself" advice.

This is literally "go fuck yourself" advice.

Scheduled Pinned Locked Moved Uncategorized
19 Posts 9 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • petrillic@hachyderm.ioP petrillic@hachyderm.io

    RE: https://mastodon.transneptune.net/@owen/116541558564007666

    This is literally "go fuck yourself" advice.

    owen@mastodon.transneptune.netO This user is from outside of this forum
    owen@mastodon.transneptune.netO This user is from outside of this forum
    owen@mastodon.transneptune.net
    wrote last edited by
    #3

    @petrillic It _deeply_ is. I ran a small CA for my own services for a while, and it was a constant thorn in my side. I can't imagine trying to persuade visitors to use it or trying to get some kid's Switch to accept those certs, nor would I want to leave them with the wreckage afterwards.

    1 Reply Last reply
    0
    • petrillic@hachyderm.ioP petrillic@hachyderm.io

      I have, quite literally, written a bunch of code that (at least used to be) is part of a major commercial CA product.

      You do not want to do this.

      Unless you hate yourself. Deeply.

      ryanc@infosec.exchangeR This user is from outside of this forum
      ryanc@infosec.exchangeR This user is from outside of this forum
      ryanc@infosec.exchange
      wrote last edited by
      #4

      @petrillic I ran a CA for my previous employer, I learned a lot, for example, fuck mTLS.

      petrillic@hachyderm.ioP glyph@mastodon.socialG 2 Replies Last reply
      0
      • ryanc@infosec.exchangeR ryanc@infosec.exchange

        @petrillic I ran a CA for my previous employer, I learned a lot, for example, fuck mTLS.

        petrillic@hachyderm.ioP This user is from outside of this forum
        petrillic@hachyderm.ioP This user is from outside of this forum
        petrillic@hachyderm.io
        wrote last edited by
        #5

        @ryanc this is the kind way to view mTLS

        ryanc@infosec.exchangeR 1 Reply Last reply
        0
        • petrillic@hachyderm.ioP petrillic@hachyderm.io

          @ryanc this is the kind way to view mTLS

          ryanc@infosec.exchangeR This user is from outside of this forum
          ryanc@infosec.exchangeR This user is from outside of this forum
          ryanc@infosec.exchange
          wrote last edited by
          #6

          @petrillic when I was interviewing for my current job, it was relevant, so I told the guy who was interviewing me "...and you could use mTLS, if you hate yourself", and from that point on we were just casually chatting.

          petrillic@hachyderm.ioP viq@social.hackerspace.plV 2 Replies Last reply
          0
          • ryanc@infosec.exchangeR ryanc@infosec.exchange

            @petrillic when I was interviewing for my current job, it was relevant, so I told the guy who was interviewing me "...and you could use mTLS, if you hate yourself", and from that point on we were just casually chatting.

            petrillic@hachyderm.ioP This user is from outside of this forum
            petrillic@hachyderm.ioP This user is from outside of this forum
            petrillic@hachyderm.io
            wrote last edited by
            #7

            @ryanc yourself, and everyone who comes after you.

            Whew 🙂 Choices.

            1 Reply Last reply
            0
            • ryanc@infosec.exchangeR ryanc@infosec.exchange

              @petrillic when I was interviewing for my current job, it was relevant, so I told the guy who was interviewing me "...and you could use mTLS, if you hate yourself", and from that point on we were just casually chatting.

              viq@social.hackerspace.plV This user is from outside of this forum
              viq@social.hackerspace.plV This user is from outside of this forum
              viq@social.hackerspace.pl
              wrote last edited by
              #8

              @ryanc @petrillic I clearly don't know enough. What are some of the reasons for "if you hate yourself"?

              ryanc@infosec.exchangeR 1 Reply Last reply
              0
              • ryanc@infosec.exchangeR ryanc@infosec.exchange

                @petrillic I ran a CA for my previous employer, I learned a lot, for example, fuck mTLS.

                glyph@mastodon.socialG This user is from outside of this forum
                glyph@mastodon.socialG This user is from outside of this forum
                glyph@mastodon.social
                wrote last edited by
                #9

                @ryanc @petrillic as you mentioned in the replies, acme-dns for lan addresses is *almost* reasonable (I also do it, it’s… fine… I am sympathetic to the OP’s desire for more reasonable treatment of .local but I have unironically recommended it to people who have been more or less satisfied with it) but running your own CA is advice from people who have only daydreamed about operating PKI infrastructure.

                keithzg@fediverse.keithzg.caK 1 Reply Last reply
                0
                • glyph@mastodon.socialG glyph@mastodon.social

                  @ryanc @petrillic as you mentioned in the replies, acme-dns for lan addresses is *almost* reasonable (I also do it, it’s… fine… I am sympathetic to the OP’s desire for more reasonable treatment of .local but I have unironically recommended it to people who have been more or less satisfied with it) but running your own CA is advice from people who have only daydreamed about operating PKI infrastructure.

                  keithzg@fediverse.keithzg.caK This user is from outside of this forum
                  keithzg@fediverse.keithzg.caK This user is from outside of this forum
                  keithzg@fediverse.keithzg.ca
                  wrote last edited by
                  #10
                  @glyph @ryanc @petrillic I find running our own CA at my work easy enough, but the scale is verrrry small and frankly I'm probably skipping a lot of steps that "real" CAs wouldn't
                  glyph@mastodon.socialG 1 Reply Last reply
                  0
                  • keithzg@fediverse.keithzg.caK keithzg@fediverse.keithzg.ca
                    @glyph @ryanc @petrillic I find running our own CA at my work easy enough, but the scale is verrrry small and frankly I'm probably skipping a lot of steps that "real" CAs wouldn't
                    glyph@mastodon.socialG This user is from outside of this forum
                    glyph@mastodon.socialG This user is from outside of this forum
                    glyph@mastodon.social
                    wrote last edited by
                    #11

                    @keithzg @petrillic @ryanc yeah everybody who eventually goes through the “find out” phase initially feels like this about operating a CA 🙃

                    glyph@mastodon.socialG 1 Reply Last reply
                    0
                    • glyph@mastodon.socialG glyph@mastodon.social

                      @keithzg @petrillic @ryanc yeah everybody who eventually goes through the “find out” phase initially feels like this about operating a CA 🙃

                      glyph@mastodon.socialG This user is from outside of this forum
                      glyph@mastodon.socialG This user is from outside of this forum
                      glyph@mastodon.social
                      wrote last edited by
                      #12

                      @keithzg @petrillic @ryanc citation: I once wrote a tool that made every user an mTLS CA in a complex dynamic trust mesh and in my darker moments I still think … maybe it could work …

                      keithzg@fediverse.keithzg.caK http_error_418@hachyderm.ioH 2 Replies Last reply
                      1
                      0
                      • petrillic@hachyderm.ioP petrillic@hachyderm.io

                        RE: https://mastodon.transneptune.net/@owen/116541558564007666

                        This is literally "go fuck yourself" advice.

                        fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                        fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                        fuzzyfuzzyfungus@cyberplace.social
                        wrote last edited by
                        #13

                        @petrillic It may be a pain; but at least there are a variety of somewhat non-obvious ways to make it actively dangerous without noticing. What's not to like?

                        1 Reply Last reply
                        0
                        • glyph@mastodon.socialG glyph@mastodon.social

                          @keithzg @petrillic @ryanc citation: I once wrote a tool that made every user an mTLS CA in a complex dynamic trust mesh and in my darker moments I still think … maybe it could work …

                          keithzg@fediverse.keithzg.caK This user is from outside of this forum
                          keithzg@fediverse.keithzg.caK This user is from outside of this forum
                          keithzg@fediverse.keithzg.ca
                          wrote last edited by
                          #14
                          @glyph @petrillic @ryanc It's been in operation a few years at work and It's Fine™ for our purposes but we're certainly not dynamically provisioning services or any such thing, it's *purely* for "make this host trusted for HTTPS purposes" and those hosts are few and static. And I definitely landed on just doing it with a few manual `openssl` calls and a convenience script or two after surveying the more fully-featured run-your-own-CA software options out there, laughing nervously, and then quickly shutting the door.
                          1 Reply Last reply
                          0
                          • viq@social.hackerspace.plV viq@social.hackerspace.pl

                            @ryanc @petrillic I clearly don't know enough. What are some of the reasons for "if you hate yourself"?

                            ryanc@infosec.exchangeR This user is from outside of this forum
                            ryanc@infosec.exchangeR This user is from outside of this forum
                            ryanc@infosec.exchange
                            wrote last edited by
                            #15

                            @viq @petrillic since revocation doesn't work worth shit, they're basically bearer tokens with extra steps

                            viq@social.hackerspace.plV petrillic@hachyderm.ioP 2 Replies Last reply
                            1
                            0
                            • R relay@relay.infosec.exchange shared this topic
                            • glyph@mastodon.socialG glyph@mastodon.social

                              @keithzg @petrillic @ryanc citation: I once wrote a tool that made every user an mTLS CA in a complex dynamic trust mesh and in my darker moments I still think … maybe it could work …

                              http_error_418@hachyderm.ioH This user is from outside of this forum
                              http_error_418@hachyderm.ioH This user is from outside of this forum
                              http_error_418@hachyderm.io
                              wrote last edited by
                              #16

                              @glyph @keithzg @petrillic @ryanc this feels like the words of someone who dumped his ex after finding out she was literally a demon from hell... every so often he thinks of the amazing sex and is halfway to dialling her number before he remembers the claw marks, the ichor, and the creeping, gibbering madness

                              1 Reply Last reply
                              1
                              0
                              • ryanc@infosec.exchangeR ryanc@infosec.exchange

                                @viq @petrillic since revocation doesn't work worth shit, they're basically bearer tokens with extra steps

                                viq@social.hackerspace.plV This user is from outside of this forum
                                viq@social.hackerspace.plV This user is from outside of this forum
                                viq@social.hackerspace.pl
                                wrote last edited by
                                #17

                                @ryanc @petrillic ah, thank you.

                                1 Reply Last reply
                                0
                                • ryanc@infosec.exchangeR ryanc@infosec.exchange

                                  @viq @petrillic since revocation doesn't work worth shit, they're basically bearer tokens with extra steps

                                  petrillic@hachyderm.ioP This user is from outside of this forum
                                  petrillic@hachyderm.ioP This user is from outside of this forum
                                  petrillic@hachyderm.io
                                  wrote last edited by
                                  #18

                                  @ryanc @viq somehow this never quite clicked this way before. This is a great description.

                                  c0dec0dec0de@hachyderm.ioC 1 Reply Last reply
                                  0
                                  • petrillic@hachyderm.ioP petrillic@hachyderm.io

                                    @ryanc @viq somehow this never quite clicked this way before. This is a great description.

                                    c0dec0dec0de@hachyderm.ioC This user is from outside of this forum
                                    c0dec0dec0de@hachyderm.ioC This user is from outside of this forum
                                    c0dec0dec0de@hachyderm.io
                                    wrote last edited by
                                    #19

                                    @petrillic @ryanc @viq oh. Oh, shit.

                                    1 Reply Last reply
                                    0
                                    Reply
                                    • Reply as topic
                                    Log in to reply
                                    • Oldest to Newest
                                    • Newest to Oldest
                                    • Most Votes


                                    • Login

                                    • Login or register to search.
                                    • First post
                                      Last post
                                    0
                                    • Categories
                                    • Recent
                                    • Tags
                                    • Popular
                                    • World
                                    • Users
                                    • Groups