5 ms·
Caddy targets single instances. No coordination is required to avoid receiving receive multiple certificates for multiple instances for same domain. Nginx has
by adobrawy 3y ago
Caddy targets single instances. No coordination is required to avoid receiving receive multiple certificates for multiple instances for same domain.
Nginx has a profit from big business that would require coordination to avoid multiple certificates. For comparison, it is worth noting that to ensure such coordination, Traefik requires an Enterprise plan and a separate agent. Such a business also often has mechanisms for storing certificates, so they do not necessarily want to integrate it into Nginx.
- francislavoie 3y agoWith Caddy, you can cluster easily by either sharing its filesystem data storage across machines, or configuring a different storage driver (redis, consul, db, etc.) and they will automatically coordinate for cert issuance. Caddy writes a lock file to the storage which prevents multiple instances from stepping on eachother's toes.
- bg24 3y agoI recently moved to Caddy. Out-of-the-box TLS, HTTP3, Dumbed-down simple configuration, static files... it has been a breath of fresh air.
- rekoil 3y agoCaddy is amazing. Still irritated that they ship it with an unprotected admin endpoint enabled by default on localhost:2019 that eats JSON and allows reconfiguration of the webserver like adding new sites that enable further attacks. Put "{ admin off }" as a separate block in the root Caddyfile to disable it.
- francislavoie 3y agoOur view is that localhost:2019 is inherently protected though - that only allows requests from the same machine. If you're running the machine with shared users, then of course it's up to you to further secure things. That said, see https://github.com/caddyserver/caddy/issues/5317 https://github.com/caddyserver/caddy/issues/5317, we are considering changing the default, but that would be a breaking change although it would likely be a transparent change for most users. The default that makes the most sense depends on the platform and installation method, which is why it's complicated.
- rekoil 3y agoSSRF is a thing, just because you trust the code doesn't mean you've eliminated all security risks. The tools we use in the industry should all have secure defaults. Glad to hear you're considering changing the default! It would be enough for me if Caddy generated a password (that's hard for attackers to predict) on first launch, set that in a config file it has write access to (autosave.json for example), and then required Basic auth using this password unless the configuration specified otherwise. My problem is that this endpoint is entirely unauthenticated.
- mholt 3y agoHave you demonstrated SSRF on a server that is not running insecure or untrusted code (i.e. is not already compromised)? We have yet to see this, but if we do see a practical demonstration, we're happy to reconsider.
- rekoil 3y agoYou've never seen an application with an SSRF vulnerability? I've encountered multiple working as a penetration tester.
- deleted 3y ago[deleted]
- account42 3y agoThis is a horrible approach to security. Bad. Bad. Bad.
- mholt 3y agoMaking decisions based on demonstration of practical attacks is "bad bad bad"?
- account42 3y agoAssuming that everyone on local host should have admin access to the web server is an extremely bad default, yes. Listening on ports that the user has not requested is bad enough but doing so without any authentication on that interface is bonkers.
- fulafel 3y agoAlso written in a memory-safeish language.
- mholt 3y agoYes -- hugely underrated. Memory safety vulnerabilities are the cause of 60-70% of exploits [0] including the infamous Heartbleed. Caddy is not susceptible to these types of vulnerabilities. That we continue to deploy C code to the edge -- including software we think is hardened like nginx or Apache or OpenSSL -- boggles my mind. [0]: https://www.memorysafety.org/docs/memory-safety/ https://www.memorysafety.org/docs/memory-safety/