7 ms·
Already thought about this. But a) the application does not require any internet connection, b) while it is possible to just get a global domain name and redire
by aurelian15 9y ago
Already thought about this. But a) the application does not require any internet connection, b) while it is possible to just get a global domain name and redirect that locally to the local server, this would require my server to hijack all DNS requests in the local network. Which I don't want to. And I don't want users having to setup DNS redirects themselves.
Edit: And don't get me wrong, I'm totally for TLS on the local network; but there should be an easy way for users to permanently mark self-signed certificates from a local address as secure.
- fulafel 9y agoThere would be no hijacking involved, just give each of your users a normal unique subdomain that you serve from the DNS. As in, user-1.yourapp.net, user-2.yourapp.net etc. If someone wants to run it in a network with no access to the DNS, you can just tell them to put that in their hosts file (or whatever local DNS setup they are using).
- JeanMarcS 9y agoDo you have the IP of your server on your local network ? Is it fixed (always the same) ? If so, that I would try something like this : - get a domain if you don’t have one - configure a subdomain (like myhomeserver.mydomain.tld) to that IP on the DNS (A record) - get a Let’s encrypt certificate using DNS validation - install the certificate on the local server I haven’t tested this with certificates, but we used to do this back in the days to avoid configuring local DNS on some small companies networks
- godzilla82 9y agoSo, are you suggesting to buy domains even for isolated networks? And then for this to work you need to connect to the internet just for DNS lookup?
- jakobegger 9y agoNo, you can use a local DNS server or put the DNS entries in your host file. No need to use the internet for DNS lookup.
- tialaramex 9y agoIn order to be assured of something's identity, it needs an actual identity to be assured of. For things on the network, this will usually be a DNS name, so we should give them a DNS name. You don't need to buy "domains", but certainly for a commercial project that makes loads of things which need names it would make sense to own a sub-domain to put all the names in. You also don't need to "connect to the internet just for DNS lookup" unless you really want to. The point of using DNS names isn't that you can look them up in DNS, it's that they're are a unique hierarchy with a central authority. There _are_ alternatives to DNS names but none of them have a trustworthy and working PKI today so you can't use them to secure anything you build. Maybe building a trustworthy PKI is hard? If you insist upon using Let's Encrypt (which is a charitable purpose and so charges $0 for certificates) perhaps because it's actually a hobby project then yes, somebody would need to control DNS records in order to periodically prove control over each name and get issued a certificate, because that's how ACME (the protocol Let's Encrypt use) decides whether to issue. Many other public CAs are for-profit companies and several already have _active_ commercial deals in which they issue certificates for devices in bulk to the name owner. If you're EXA Metal Poles Europe and you're making 50 000 devices named in the range pole0000.foo.example.com through poleFFFF.foo.example.com they are quite happy to issue you, the legitimate owners of example.com with 50 000 certificates for those devices in exchange for money.
- __david__ 9y agoAt some level, a certificate is an identity. If I’ve trusted a cert then I know that anyone using it has the private key, no matter their IP or dns name. Being able to do that for a local device would be very nice—I could connect to whatever up it dhcp-ed to and be sure I was talking to the right thing.
- tialaramex 9y agoThat deserves a hard stare. If I trust the certificate on my chat server to be _the certificate for my chat server_ that doesn't suddenly make it OK to present that certificate if you're claiming to be my bank, or my operating system vendor, or Hacker News. The local device should have a _name_ and then we can issue it a certificate for that _name_ and know we're really talking to the same thing as last time. DHCP and other address allocation protocols don't (needn't) change the name.
- e12e 9y ago> there should be an easy way for users to permanently mark self-signed certificates from a local address as secure. I'm not sure I agree that that's where ux need improvement. Microsoft already have a pretty "easy" solution for pushing locally trusted ca certs, but only in an "enterprise" environment. Most/all Linux distros will allow pushing to /etc/ssl/certs/ca-certificates (via eg /usr/local/share/ca-certificates and update-ca-certificates). But that doesn't help as long as browsers work hard to be "special", and manage their own trust. Being able to mark some nets as trusted/local might help - both with :::1 and with vpns.