Elektrine lite

← Feed

@ryanc@infosec.exchange

Post #2563456

2026-05-08 23:48 UTC

@owen@mastodon.transneptune.net I use acme-dns authorized subdomain certificates on my lab, this is nearly as unreasonable as running a CA for my home network. And I have run one on a corporate network.

Replies (3)

  • @azonenberg@ioc.exchange 2026-05-08 23:57

    @ryanc@infosec.exchange @owen@mastodon.transneptune.net I mean I have my own local CA with two different intermediate CAs, but I also run my own DNS. And I need the CA to issue client certificates to VPN clients (I have a ban on password authentication, to the extent supported by the service, for anything network reachable). Once you have that infrastructure in place also issuing your own HTTPS certs is straightforward enough. But it's certainly not something the average person wants to deal with.

    Open ##2563457

  • @dalias@hachyderm.io 2026-05-09 00:08

    @ryanc@infosec.exchange @owen@mastodon.transneptune.net With DNS-PERSIST-01 it'll be easy to get real certs for your LAN-only devices.

    Open ##2563462

  • @astraluma@tacobelllabs.net 2026-05-09 00:16

    @ryanc@infosec.exchange @owen@mastodon.transneptune.net we're trying to figure this out for the local makerspace Do not recommend

    Open ##2563476