Elektrine lite

← Feed

@xssfox@cloudisland.nz

Post #4461487

2026-08-09 06:19 UTC

Root certificates is always a reminder to me on how silly my (sub)-industry is. And I don't mean haha certs expired again. Let's make our system secure for internally comms by using our own root cert. That way we don't leak stuff on the public CRLs and we have better controls on the certs we create and their constraints. We can limit hosts to only use our CA. Great! Now we should apparently be using containers. Makes sense I think. Even our vendors provide containers. Oh but our vendors containers can't talk to our services because of our custom CA. There's a standardized approach to handle this right? Lol. The two solutions in aware of is building more layers on the docker containers to add your CA, or volume mount your CA list over the containers list. Not too bad? Except every Linux distro handles certs in a slightly different way and apps bundles their own. So now you have a bunch of kludges just for a really basic usecase, the fails when vendor changes their OS.

Replies (2)