3 ms·
does it work with "tls internal" or do the certs need to be signed by an outside CA for HTTP/3 to be enabled.
by howeyc 4y ago
does it work with "tls internal" or do the certs need to be signed by an outside CA for HTTP/3 to be enabled.
- mholt 4y agoYes it works with self-signed certificates!
- superkuh 4y agoI'm really glad to hear this is an option. But will browsers accessing the website accept the self-signed certs when setting up the TLS connection required by QUIC? I don't know how they behave. I'm genuinely asking.
- francislavoie 4y agoYes they do, as long as you installed Caddy's root CA cert in the browser's trust store. Caddy will attempt to install it automatically with https://github.com/smallstep/truststore https://github.com/smallstep/truststore if possible (usually requires root) but if it fails you can try again with "sudo caddy trust". You might be using a client or trust store that isn't supported though, in which case you'll need to install the root cert manually.
- superkuh 4y agoWhat if I just want to generate and use a self signed cert without any CA involvement? I do that with HTTP all the time and it works for the public web even if the browsers like to scaremonger about it. Does a QUIC connection work without a CA (corporate) root cert being referenced?
- francislavoie 4y agoTo be clear, Caddy itself manages its own internal CA. It's the same thing as self signing except you have a root cert you can trust, to trust every cert Caddy generates; that's instead of having individual self signed certificates. This makes it significantly easier if you have many subdomains for each of your services, etc. It has nothing to do with corporate CAs, no external entities. QUIC/HTTP3 use the same TLS stack as H1/H2, same things are trusted. So there's no difference there.
- mholt 4y ago(Fun-fact, "self-signed" certs also have "CA involvement" -- it's just that the leaf is also the signing authority, which is generally bad practice. Caddy does this properly with a separate signing root -- that stays offline and has long validity -- as Francis explained.)