Post #2563456
2026-05-08 23:48 UTC
Replies (3)
-
@azonenberg@ioc.exchange 2026-05-08 23:57
@ryanc@infosec.exchange @owen@mastodon.transneptune.net I mean I have my own local CA with two different intermediate CAs, but I also run my own DNS. And I need the CA to issue client certificates to VPN clients (I have a ban on password authentication, to the extent supported by the service, for anything network reachable). Once you have that infrastructure in place also issuing your own HTTPS certs is straightforward enough. But it's certainly not something the average person wants to deal with.
-
@dalias@hachyderm.io 2026-05-09 00:08
@ryanc@infosec.exchange @owen@mastodon.transneptune.net With DNS-PERSIST-01 it'll be easy to get real certs for your LAN-only devices.
-
@astraluma@tacobelllabs.net 2026-05-09 00:16
@ryanc@infosec.exchange @owen@mastodon.transneptune.net we're trying to figure this out for the local makerspace Do not recommend