5 ms·
Unlike LetsEncrypt, it supports certificates for IP addresses, which is nice for hobbyists who don’t want to buy a domain.
by surround 6y ago
Unlike LetsEncrypt, it supports certificates for IP addresses, which is nice for hobbyists who don’t want to buy a domain.
- scaladev 6y agoWhy would you necessarily buy a domain? I use lots of free domains in .tk and .cf, they work great. https://freenom.com/ https://freenom.com/ For frequently changing IPs there are also services like http://duckdns.org http://duckdns.org which provide you with a third-level domain like xyz.duckdns.org
- surround 6y agoWhy get a domain, if you don’t need one? The free .tk domains are only free for 1 year. And even if you are only going to use it for a year, some people would rather not give out their credit card number for a free trial.
- scaladev 6y agoPlease stop spreading misinformation. You don't need a card, you don't have to provide any identification at all. The domains are free for as long as you want (I've been using one for the last 3 years), you just have to click a button once a year, and freenom sends you emails two weeks in advance.
- spurgu 6y agoCorrect. I just got one with a fake name and address, no phone number needed, nor a credit card.
- surround 6y agoPerhaps I’m mistaken, but I believe at one point in time, years ago, they required a card for the free registration. It certainly wasn’t my intent to spread misinformation. Now I’m wondering, how does Freenom make money?
- afarviral 6y agoI have recently tried to pick up a domain name on Freenom and had extreme difficulty getting the website to respond and issue me a domain name. Once I finally locked one down that I liked, my account was dissapeared without a courtesy email or anything. To be fair I was using obviously anonymous/pseudonym details, but I would have still expected a courtesy email.
- da_big_ghey 6y agoNo, they can be renewed for another free year indefinitely, as far as I know. I don't believe they require a credit card number, either. I've had a few freenom domains I've renewed for several years in a row and just got some new ones a few months ago; it's a very useful service.
- nix23 6y agoDon't forget freedns.
- da_big_ghey 6y agoDuckdns is good, though I really like Hurricane Electric's DNS: dns.he.net/ It offers a lot for free; I started using it when I moved off cloudflare and have quite liked it.
- IgorPartola 6y agoI really like and use HE.net but it’s API is definitely not ideal, last I checked.
- 1vuio0pswjnm7 6y ago"Why would you necessarily buy a domain?" E-mail is one example. Technically domain names are not necessary to successfully send own mail with own server, i.e., without using a 3rd party email provider. E-mail predates DNS; mail software has always supported IP addresses. However, today, the dominant 3rd party e-mail providers will reject mail coming from an IP address not associated with a domain name.
- hackerbee 6y agoThe patchwork of anti-phishing and anti-spamming measures like SPF and DKIM require DNS TXT records. Allowing mail from an IP address would likely be used almost exclusively for spamming.
- snazz 6y agoI know three people personally who used Freenom domains and lost access at some point. I've never actually been successful at getting it to give me a domain in the first place, but the last time I tried was years ago. So definitely be careful hosting anything vaguely important on one of those domains.
- stevewillows 6y agoI've got one domain with freenom. You have to manually renew it every year, but otherwise it's fine for totally useless projects. For anything with even the smallest bit of value, a cheap tld like .party can be had for a decade for around $20.
- auscompgeek 6y agoI had a Freenom account several years ago. At one point they decided that I wouldn't be allowed to register any new domains on that account, or renew any of my existing domains, so I lost a few domain names. I still don't know why.
- djsumdog 6y ago.ml domains tend to disappear when they get popular, and sometimes you can't even buy them at that point. With those free DNSes, you get what you pay for. Don't use them for anything important.
- a3_nm 6y agoInteresting, thanks! Do you have a link to know more about people to whom this happened?
- dheera 6y agoIt's usually harder to buy a static IP than a domain ...
- gruez 6y agoAccording to the CAB baseline requirements it doesn't look like you need to prove ownership of the IP address to get a certificate for it. https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-1.7.3.pdf https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-... (section 3.2.2.5.1)
- calcifer 6y ago> section 3.2.2.5.1 There is no such section?
- gruez 6y agosearching for "3.2.2.5.1" works just fine in firefox's pdf.js. For reference it's on page 40
- tialaramex 6y agoAlmost all modern documents about certificate policy have the same structure, a structure described in RFC 3647. This makes it easier to find what you're looking for in somebody else's policy document and to verify they ticked all the boxes. If they've got a rule about Certificate Revocation for example that'll go in section 4.9. So there's going to be a section 3 about "Identification and Authentication" and it's going to have a subsection 3.2 "Initial Identity Validation" and that's going to have a sub-subsection 3.2.2 about how we figure out who this actually is we're talking to, and so these sections will be further divided. 3.2.2.4.x is the "Ten Blessed Methods" (these days there are rather more than ten) for how we validate DNS names in the Web PKI).
- carbocation 6y agoI have one domain that is shared by all of my projects, which sit on subdomains. It's a happy in-between for me.
- afarviral 6y agoWoohoo, that's just what I was looking for.
- chaz6 6y agoI really wish ESNI used certs for IP addresses instead of relying on a DNS hack. It could do onion-style security with the outer handshake protected by the IP address cert, and the inner layer protected by the domain name cert.