4 ms·
It would be nice to see this paired with more widespread support for the Name Constraints TLS extension, which would in theory allow internal CAs to be restrict
by nbadg 3y ago
It would be nice to see this paired with more widespread support for the Name Constraints TLS extension, which would in theory allow internal CAs to be restricted to issuing certificates for .internal domains. That would open up a lot of very interesting applications in terms of streamlining HTTPS on local networks, for example, ACME on openWRT routers.
- 8organicbits 3y agoAbsolutely. We're getting closer, but it's hard to measure what actually supports it as bettertls (the caniuse equivalent in this space) doesn't track it. https://github.com/Netflix/bettertls/issues/19 https://github.com/Netflix/bettertls/issues/19
- teleclimber 3y agoNote there was a W3C community group that explored the "HTTPS on local networks" question. It's closed now but they wrote use cases and proposals: https://www.w3.org/community/httpslocal/ https://www.w3.org/community/httpslocal/ https://httpslocal.github.io/proposals/ https://httpslocal.github.io/proposals/ https://httpslocal.github.io/usecases/ https://httpslocal.github.io/usecases/ I wish some of this work would continue as well.
- deleted 3y ago[deleted]