3 ms·
Agree. It triggers me a little when folks complain about HTTPS. Nowadays you have a wealth of tools to trivialize TLS certificate tasks. Public TLS cert? Lets
by umactually1 3y ago
Agree.
It triggers me a little when folks complain about HTTPS. Nowadays you have a wealth of tools to trivialize TLS certificate tasks.
Public TLS cert? LetsEncrypt + certbot (or any of the other zillion great ACME clients/libraries out there).
Self-hosted PKI for private/test use? Smallstep CLI (https://smallstep.com/docs/step-cli/ https://smallstep.com/docs/step-cli/) is good. And honestly, the raw `openssl` commands to barf out a root selfsigned cert aren't that difficult and number as less than 5 shell invocations that you could have in your history or a bash function or something.
Self-hosted PKI with extra steps that you already did because you have a Kubernetes cluster for some other reason? cert-manager will take care of pretty much everything.
These days the "hardest" part is sneaking your CA chain into the appropriate browsers / services you're using/testing, but even that is a few moments of inconvenience at best.
- jeroenhd 3y agoGetting a CA into a Mastodon server is an adventure of its own. Setting up the CA isn't that hard even without smallstep (copy/paste three or four commands and you're good to start testing) but getting the CA working where it needs to work is a massive pain. Everything has a different certificate store, sometimes compiled into the binaries, and getting stuff talking to each other is a massive pain. For browsers, importing certificates comes down to just searching "certificate" in the settings. It's everything else that's broken, in my experience.
- fuomag9 3y agoI agree. For example home assistant OS has a custom cert store that is reset on boot and there’s no way to make persistent modifications without recurring to hacks such as this one https://github.com/Athozs/hass-additional-ca https://github.com/Athozs/hass-additional-ca
- plagiarist 3y agoEnraging on a tool that offers user login from a webpage. You should be able to add DNS records to your gateway and not have to deal with public CAs to access it by name with TLS.
- shadowgovt 3y agoYep. As a datapoint: I set up my own Mastodon server behind a Cloudflare tunnel and completed every step except the cert, eventually opting to just tell Cloudflare to ignore the cert config. The default solution doesn't work on a shared host where you don't have control over running your own services and opening your own ports, only serving static pages instead using a shared web server.
- nottorp 3y ago> Nowadays you have a wealth of tools to trivialize TLS certificate tasks. Trivialize what? You have to learn the tools. When you're paid for it or actually believe that signing everything is useful, you're willing to spend the time. In the original article it looks like the poster already went over their time budget by a lot without even getting to researching if these tools exist.
- layer8 3y agoThe lack of a standard way to specify your trusted CAs on a system or network is one of the biggest hassles in that area. It’s typically all bespoke configuration, and often not well documented.