5 ms·
I didn't see that post, but if you control the DNS for a domain you can use the DNS challenge with Let's Encrypt.
by jameshclark 9y ago
I didn't see that post, but if you control the DNS for a domain you can use the DNS challenge with Let's Encrypt.
- rb808 9y agoMost people dont control a domain.
- gsich 9y agoThen you usually don't need a certificate from a CA. Just selfsign.
- fps 9y agoThis seems like it's going in circles, but, if you selfsign modern browsers display a big scary warning. If you're making a device or software meant to live behind a firewall and to be accessed from a browser, users will either have to install your CA in their browsers, or deal with the big scary warning. Both of which are bad.
- gsich 9y agoIf you don't have a domain, chances are that you don't provide service to normal users. Or to users at all besides yourself.
- pessimizer 9y ago> chances are that you don't provide service to normal users. Or to users at all besides yourself. I think that's the point. Creating friction that scares normie users when people are using web UIs on local networks puts non-cloud based products at a disadvantage against the centralized giants.
- Ajedi32 9y agoMozilla does though. So if their plan is to "offer subdomains on mozilla-iot.com" then they just need to set it up so that their infrastructure will fulfill the DNS challenge for the user's device when it requests a new cert.
- falcor84 9y agoMaybe this is a problem. I'd say that in the world we live in, getting a domain is as useful as getting a passport. It costs a bit of money to get and renew and is a bit of a hassle, but it opens a lot of doors.
- dredmorbius 9y agoWhich itself raises several questions: 1. Should most people have access to a domain they control? 2. Should there be a standard for nonroutable / nonpublic domains? (.lan and .localdomain are two of which I'm generally aware) 3. How should browsers deal with hosts and/or domains which are not and can not be on the public Internet? 4. How the hell did we get into this mess? I'm kicking around the notion of relaxing various aspects of the problem domain and seeing where we end up. It's mind-numbingly bad, though.
- dredmorbius 9y agoAlso: if we don't use the domain registration system to proxy for individual sites and presence on the Internet, then what alternatives might be substituted? Note that domains don't solve the problem of a third-party controlling your point-of-access or presence, they only move it elsewhere.