One SSL cert, three servers. Which one generates the private key?
Generate-where-used breaks once a cert is shared. The key moves anyway. Design that, or it becomes scp in a cron job.
https://www.certkit.io/blog/ssl-certificate-multiple-servers
#SSL #PKI
Part 5 of my homelab downsizing series: a week building the wrong cert automation (acme-proxy — turns out it doesn't support Cloudflare DNS-01), then six days and three attempts standing up FreeIPA as a subordinate CA before shelving it for Samba AD. Two burned signing ceremonies, one silently-discarded private key. #homelab #pki #freeipa #selfhosted
https://homelab.tod.net/posts/downsizing-the-homelab/pki-decision-journal/
The longest SSL certificate you can buy today is 200 days. By 2029 it will be 47.
Revocation never worked, so the industry is killing long lifespans instead.
@toddhgardner@hachyderm.io broke down the why on RunAs Radio.
https://runasradio.com/Shows/Show/1041
#SSL #PKI
You've seen all posts