3 ms·
>Replace self-signed certs with a self-signed CA? [...], why not just use LE and get a real cert? I went back and forth between self-signed CA vs LetsEncrypt.
by jasode 3y ago
>Replace self-signed certs with a self-signed CA? [...], why not just use LE and get a real cert?
I went back and forth between self-signed CA vs LetsEncrypt.
I liked the self-signed CA root because you can create end-entity certificates for internal ip addresses such as 192.168.1.13 instead of domain names. (No domain name purchase and no public DNS records pointing to 192.168.1.13 required.) The public SSL services like Let'sEncrypt and ZeroSSL can't issue certs for RFC1918 ip addresses -- for obvious reasons.
On the other hand, I didn't want to import my custom CA root certificate into all 8+ devices around the house. (desktops+laptops+phones+tablets+etc.) So, Let'sEncrypt won in my case on that basis.
- luma 3y agoIf you're going to the effort to run a CA, why not also run DNS? I say this as a guy who runs an internal CA and eventually just implemented LE due to all the problems with trusting internal CAs and getting that to work across all devices.