3 ms·
Sign your own? It’s your home!
by someguydave 2y ago
Sign your own? It’s your home!
- accrual 2y agoI've thought about running a local CA, but wouldn't one need to have all of their devices configured to trust the local CA in addition to issuing certs to your services? I've been getting by just clicking through the TLS warnings for my LAN services, most browsers remember the choice for a couple days at least.
- gclawes 2y agoI've been doing this for a while with SmallStep CA: https://github.com/smallstep/certificates https://github.com/smallstep/certificates It's a bit of a pain to load a cert onto every device (easier with stuff like Ansible if you have a bunch of linux devices), but manageable. And it lets me do proper trusted TLS for a lot of stuff that would otherwise be self-signed. edit: It's also just a fun homelab project to see what it's like to run a full production-ish PKI setup. One thing I recommend is to add X509v3 Name Constraints extensions to your root CA if you go down this path. It prevents the CA from being abused to MITM you for other domains (at least for browsers/clients that respect names constraints) X509v3 Name Constraints: critical Permitted: DNS:home.arpa DNS:.home.arpa IP:10.0.0.0/255.0.0.0 IP:172.16.0.0/255.240.0.0 IP:192.168.0.0/255.255.0.0
- eddd-ddde 2y agoAt that point just buy a proper domain. That ought to be easier than setting up a custom CA.
- someguydave 2y agoit depends on your use case, but yes you would probably need to load at least your browser with your own CA. It’s a good hygiene to manage your own keys though