3 ms·
But it runs in my LAN.
by arpa 5y ago
But it runs in my LAN.
- Zekio 5y agoyou can use lets encrypt certificates on your lan using DNS verification
- arpa 5y agoeffort / gain ratio is crap tho. Especially assuming IPv4 and reasonable firewalling.
- Zekio 5y agoeffort is basically none, aside from getting an API key from Cloudflare(could be any provider really) and then downloading the version of Caddy that includes supports Cloudflare DNS verification in terms of gains you get the benefit of easy to remember names, and you don't share everything in plaintext which is becoming more and more important as we get more and more devices on our LANs
- defanor 5y agoFWIW, the setup can be simpler and more portable without a specialized HTTP server and with a standardized protocol (RFC 2136): just certbot and its python3-certbot-dns-rfc2136. Edit: certbot has plugins for a bunch of custom APIs too.
- tedunangst 5y agoIt's may be simpler to use split horizon DNS and http verification outside the lan instead of dealing with DNS challenges.
- pixl97 5y ago"It's me, UR hax0r in your I0T, steelin your unencrypted packets"
- jeppesen-io 5y agoThere's a reason google and other wifi hardware providers are restricting internet DNS lookups for rfc 1918 addressed. Just because it's on your lan does not mean you're not vulnerable to attack from outside True, tls won't make a dramatic improvement, but it's still and improvement