Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Well isn't learning how to run your own CA a lot of fun?

Well isn't learning how to run your own CA a lot of fun?

Scheduled Pinned Locked Moved Uncategorized
27 Posts 16 Posters 6 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • neil@mastodon.neilzone.co.ukN neil@mastodon.neilzone.co.uk

    Well isn't learning how to run your own CA a lot of fun?

    And by "fun", I mean "debugging".

    And by "a lot", I mean "a looooooooooot".

    I am making progress, today around SAN and Firefox, but this is a bit like plodding around in treacle.

    (I'm not looking for advice, although sympathy is welcome :))

    wurzelmann@mastodon.wurzelmann.atW This user is from outside of this forum
    wurzelmann@mastodon.wurzelmann.atW This user is from outside of this forum
    wurzelmann@mastodon.wurzelmann.at
    wrote last edited by
    #2

    @neil *sends some sympathy your way*

    1 Reply Last reply
    0
    • neil@mastodon.neilzone.co.ukN neil@mastodon.neilzone.co.uk

      Well isn't learning how to run your own CA a lot of fun?

      And by "fun", I mean "debugging".

      And by "a lot", I mean "a looooooooooot".

      I am making progress, today around SAN and Firefox, but this is a bit like plodding around in treacle.

      (I'm not looking for advice, although sympathy is welcome :))

      greenskyoverme@ohai.socialG This user is from outside of this forum
      greenskyoverme@ohai.socialG This user is from outside of this forum
      greenskyoverme@ohai.social
      wrote last edited by
      #3

      @neil What is a CA?

      9 prsfalken@mastodon.socialP neil@mastodon.neilzone.co.ukN 3 Replies Last reply
      0
      • neil@mastodon.neilzone.co.ukN neil@mastodon.neilzone.co.uk

        Well isn't learning how to run your own CA a lot of fun?

        And by "fun", I mean "debugging".

        And by "a lot", I mean "a looooooooooot".

        I am making progress, today around SAN and Firefox, but this is a bit like plodding around in treacle.

        (I'm not looking for advice, although sympathy is welcome :))

        matthewcroughan@social.defenestrate.itM This user is from outside of this forum
        matthewcroughan@social.defenestrate.itM This user is from outside of this forum
        matthewcroughan@social.defenestrate.it
        wrote last edited by
        #4
        How come you're bothering to do it?
        brunogirin@mastodon.me.ukB neil@mastodon.neilzone.co.ukN 2 Replies Last reply
        0
        • greenskyoverme@ohai.socialG greenskyoverme@ohai.social

          @neil What is a CA?

          9 This user is from outside of this forum
          9 This user is from outside of this forum
          9pfs@tilde.zone
          wrote last edited by
          #5

          @GreenSkyOverMe @neil certificate authority

          1 Reply Last reply
          0
          • neil@mastodon.neilzone.co.ukN neil@mastodon.neilzone.co.uk

            Well isn't learning how to run your own CA a lot of fun?

            And by "fun", I mean "debugging".

            And by "a lot", I mean "a looooooooooot".

            I am making progress, today around SAN and Firefox, but this is a bit like plodding around in treacle.

            (I'm not looking for advice, although sympathy is welcome :))

            9 This user is from outside of this forum
            9 This user is from outside of this forum
            9pfs@tilde.zone
            wrote last edited by
            #6

            @neil good luck!

            1 Reply Last reply
            0
            • matthewcroughan@social.defenestrate.itM matthewcroughan@social.defenestrate.it
              How come you're bothering to do it?
              brunogirin@mastodon.me.ukB This user is from outside of this forum
              brunogirin@mastodon.me.ukB This user is from outside of this forum
              brunogirin@mastodon.me.uk
              wrote last edited by
              #7

              @matthewcroughan @neil
              My question exactly. Why?

              1 Reply Last reply
              0
              • greenskyoverme@ohai.socialG greenskyoverme@ohai.social

                @neil What is a CA?

                prsfalken@mastodon.socialP This user is from outside of this forum
                prsfalken@mastodon.socialP This user is from outside of this forum
                prsfalken@mastodon.social
                wrote last edited by
                #8

                @GreenSkyOverMe @neil Something you usually don't selfhost and if you do ... Avoid to mess with

                XD

                (Certificate authority, if I'm not mistaken)

                greenskyoverme@ohai.socialG 1 Reply Last reply
                0
                • neil@mastodon.neilzone.co.ukN neil@mastodon.neilzone.co.uk

                  Well isn't learning how to run your own CA a lot of fun?

                  And by "fun", I mean "debugging".

                  And by "a lot", I mean "a looooooooooot".

                  I am making progress, today around SAN and Firefox, but this is a bit like plodding around in treacle.

                  (I'm not looking for advice, although sympathy is welcome :))

                  graves501@fosstodon.orgG This user is from outside of this forum
                  graves501@fosstodon.orgG This user is from outside of this forum
                  graves501@fosstodon.org
                  wrote last edited by
                  #9

                  @neil Are you doing okay, Neil? Who has a gun pointing at you and telling you to run your own CA? Is it @babe again? 👀

                  1 Reply Last reply
                  0
                  • greenskyoverme@ohai.socialG greenskyoverme@ohai.social

                    @neil What is a CA?

                    neil@mastodon.neilzone.co.ukN This user is from outside of this forum
                    neil@mastodon.neilzone.co.ukN This user is from outside of this forum
                    neil@mastodon.neilzone.co.uk
                    wrote last edited by
                    #10

                    @GreenSkyOverMe Certificate Authority

                    greenskyoverme@ohai.socialG 1 Reply Last reply
                    0
                    • neil@mastodon.neilzone.co.ukN neil@mastodon.neilzone.co.uk

                      Well isn't learning how to run your own CA a lot of fun?

                      And by "fun", I mean "debugging".

                      And by "a lot", I mean "a looooooooooot".

                      I am making progress, today around SAN and Firefox, but this is a bit like plodding around in treacle.

                      (I'm not looking for advice, although sympathy is welcome :))

                      seabass@social.seabass.systemsS This user is from outside of this forum
                      seabass@social.seabass.systemsS This user is from outside of this forum
                      seabass@social.seabass.systems
                      wrote last edited by
                      #11

                      @neil I look forward to the blog post for this one! Sounds like a more challenging project than usual.

                      1 Reply Last reply
                      0
                      • neil@mastodon.neilzone.co.ukN neil@mastodon.neilzone.co.uk

                        Well isn't learning how to run your own CA a lot of fun?

                        And by "fun", I mean "debugging".

                        And by "a lot", I mean "a looooooooooot".

                        I am making progress, today around SAN and Firefox, but this is a bit like plodding around in treacle.

                        (I'm not looking for advice, although sympathy is welcome :))

                        justine@snac.smithies.me.ukJ This user is from outside of this forum
                        justine@snac.smithies.me.ukJ This user is from outside of this forum
                        justine@snac.smithies.me.uk
                        wrote last edited by
                        #12
                        Sending my deepest sympathies to you at these trying times. But letting you know that things will get better.
                        1 Reply Last reply
                        0
                        • matthewcroughan@social.defenestrate.itM matthewcroughan@social.defenestrate.it
                          How come you're bothering to do it?
                          neil@mastodon.neilzone.co.ukN This user is from outside of this forum
                          neil@mastodon.neilzone.co.ukN This user is from outside of this forum
                          neil@mastodon.neilzone.co.uk
                          wrote last edited by
                          #13

                          @matthewcroughan

                          There are some services that I run where I would like TLS, would prefer not to expose them to the Internet, am not keen on moving around Let's Encrypt cert, and would prefer them to be trusted certificates rather than self-signed certificates, to work better on mobile devices.

                          Also, a fun learning exercise.

                          1 Reply Last reply
                          0
                          • neil@mastodon.neilzone.co.ukN neil@mastodon.neilzone.co.uk

                            @GreenSkyOverMe Certificate Authority

                            greenskyoverme@ohai.socialG This user is from outside of this forum
                            greenskyoverme@ohai.socialG This user is from outside of this forum
                            greenskyoverme@ohai.social
                            wrote last edited by
                            #14

                            @neil thx

                            1 Reply Last reply
                            0
                            • prsfalken@mastodon.socialP prsfalken@mastodon.social

                              @GreenSkyOverMe @neil Something you usually don't selfhost and if you do ... Avoid to mess with

                              XD

                              (Certificate authority, if I'm not mistaken)

                              greenskyoverme@ohai.socialG This user is from outside of this forum
                              greenskyoverme@ohai.socialG This user is from outside of this forum
                              greenskyoverme@ohai.social
                              wrote last edited by
                              #15

                              @prsfalken thx

                              1 Reply Last reply
                              0
                              • neil@mastodon.neilzone.co.ukN neil@mastodon.neilzone.co.uk

                                Well isn't learning how to run your own CA a lot of fun?

                                And by "fun", I mean "debugging".

                                And by "a lot", I mean "a looooooooooot".

                                I am making progress, today around SAN and Firefox, but this is a bit like plodding around in treacle.

                                (I'm not looking for advice, although sympathy is welcome :))

                                colinthemathmo@mathstodon.xyzC This user is from outside of this forum
                                colinthemathmo@mathstodon.xyzC This user is from outside of this forum
                                colinthemathmo@mathstodon.xyz
                                wrote last edited by
                                #16

                                @neil Two things:

                                (a) What's a "CA" in this context?

                                (b) *Sympathy*

                                neil@mastodon.neilzone.co.ukN 1 Reply Last reply
                                0
                                • colinthemathmo@mathstodon.xyzC colinthemathmo@mathstodon.xyz

                                  @neil Two things:

                                  (a) What's a "CA" in this context?

                                  (b) *Sympathy*

                                  neil@mastodon.neilzone.co.ukN This user is from outside of this forum
                                  neil@mastodon.neilzone.co.ukN This user is from outside of this forum
                                  neil@mastodon.neilzone.co.uk
                                  wrote last edited by
                                  #17

                                  @ColinTheMathmo Certificate Authority

                                  1 Reply Last reply
                                  0
                                  • neil@mastodon.neilzone.co.ukN neil@mastodon.neilzone.co.uk

                                    Well isn't learning how to run your own CA a lot of fun?

                                    And by "fun", I mean "debugging".

                                    And by "a lot", I mean "a looooooooooot".

                                    I am making progress, today around SAN and Firefox, but this is a bit like plodding around in treacle.

                                    (I'm not looking for advice, although sympathy is welcome :))

                                    bencurthoys@mastodon.socialB This user is from outside of this forum
                                    bencurthoys@mastodon.socialB This user is from outside of this forum
                                    bencurthoys@mastodon.social
                                    wrote last edited by
                                    #18

                                    @neil The best part about debugging anything to do with certificates or encryption or security is that any useful debugging information is a security leak... so you don't get any. Either it works, or it doesn't work and it refuses to tell you why.

                                    Sometimes it's mathematically impossible for it to tell you why. Once I lost more than a day working out why, when I hashed a string, I got a different hash value than was expected, when my hash function returned the same expected value on test data.

                                    bencurthoys@mastodon.socialB 1 Reply Last reply
                                    0
                                    • bencurthoys@mastodon.socialB bencurthoys@mastodon.social

                                      @neil The best part about debugging anything to do with certificates or encryption or security is that any useful debugging information is a security leak... so you don't get any. Either it works, or it doesn't work and it refuses to tell you why.

                                      Sometimes it's mathematically impossible for it to tell you why. Once I lost more than a day working out why, when I hashed a string, I got a different hash value than was expected, when my hash function returned the same expected value on test data.

                                      bencurthoys@mastodon.socialB This user is from outside of this forum
                                      bencurthoys@mastodon.socialB This user is from outside of this forum
                                      bencurthoys@mastodon.social
                                      wrote last edited by
                                      #19

                                      @neil The answer, it turns out, is that the string was being built from a GUID, and their platform serialised the GUID with lowercase hex and mine with uppercase hex, and your eye doesn't notice the case of the letters when looking at hex values, so I couldn't see that they were different.

                                      bencurthoys@mastodon.socialB 1 Reply Last reply
                                      0
                                      • bencurthoys@mastodon.socialB bencurthoys@mastodon.social

                                        @neil The answer, it turns out, is that the string was being built from a GUID, and their platform serialised the GUID with lowercase hex and mine with uppercase hex, and your eye doesn't notice the case of the letters when looking at hex values, so I couldn't see that they were different.

                                        bencurthoys@mastodon.socialB This user is from outside of this forum
                                        bencurthoys@mastodon.socialB This user is from outside of this forum
                                        bencurthoys@mastodon.social
                                        wrote last edited by
                                        #20

                                        @neil So. Sympathy.

                                        1 Reply Last reply
                                        0
                                        • neil@mastodon.neilzone.co.ukN neil@mastodon.neilzone.co.uk

                                          Well isn't learning how to run your own CA a lot of fun?

                                          And by "fun", I mean "debugging".

                                          And by "a lot", I mean "a looooooooooot".

                                          I am making progress, today around SAN and Firefox, but this is a bit like plodding around in treacle.

                                          (I'm not looking for advice, although sympathy is welcome :))

                                          neil@mastodon.neilzone.co.ukN This user is from outside of this forum
                                          neil@mastodon.neilzone.co.ukN This user is from outside of this forum
                                          neil@mastodon.neilzone.co.uk
                                          wrote last edited by
                                          #21

                                          You can expect a riveting blogpost in due course.

                                          And by "riveting", I mean "utterly tedious and unnecessary unless you, too, have the misfortune to want to run your own certificate authority".

                                          gary_alderson@infosec.exchangeG hannes@social.coopH brunogirin@mastodon.me.ukB 3 Replies Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups