4 ms·
TLS always felt like a scary beast to me until I started writing Go. The crypto/tls package is amazing and makes doing incredible things with TLS super easy. We
by eandre 5y ago
TLS always felt like a scary beast to me until I started writing Go. The crypto/tls package is amazing and makes doing incredible things with TLS super easy. We're using it in lots of interesting ways behind the scenes for Encore, leveraging Vault, a custom CA, SPIFFE for workload identity and more.
I haven't read the book, but learning more about TLS is easily one of the best time investments I've made.
- rad_gruchalski 5y ago> TLS always felt like a scary beast to me until I started writing Go. The crypto/tls package is amazing and makes doing incredible things with TLS super easy. This x100. I have been recently developing an embedded CA for a gRPC service in golang. Issuing a root, intermediate, server and a client cert for mtls is less than 350 lines of code. It’s incredible. I’ve written more about it here: https://gruchalski.com/posts/2021-03-28-firebuild-rootfs-grpc-with-mtls/ https://gruchalski.com/posts/2021-03-28-firebuild-rootfs-grp....
- fierro 5y agojust curious, what do you need SPIFEE workload identity for? I've used it in the past for building something like Tailscale
- eandre 5y agoWe use it as part of mTLS to provide access to application metadata. It doesn't need to be SPIFFE but it made sense for our use case :)
- fierro 5y agoI see, so a workload spins up and wants to learn something about itself and uses identity verification to gain access to it? My use case was an untrusted node getting a centrally issued key to join a p2p VPN