4 ms·
One downside of self-signed certs is that browsers will to upgrade all localhost ports to HTTPS thanks to HSTS. In practical terms, that meant: - we needed to
by sa46 2y ago
One downside of self-signed certs is that browsers will to upgrade all localhost ports to HTTPS thanks to HSTS. In practical terms, that meant:
- we needed to upgrade all dev servers to serve both HTTPS and HTTP.
- we downgraded server to server comms to HTTP (something about invalid cert chain)
I think the ideal solution is to use “local” domain names but that requires a DNS resolver (via Tailscale or similar).
- jck 2y agoI run some software on a raspberry pi at home. This pattern works very well for me: - services exposed via caddy(configured to use my domain on cloudflare for SSL) - my lan dns resolver(adgaurd home) is configured to rewrite these domains to local IP. Specifically, the rewrite rule looks like `homeassistant.mydomain.com -> rpi.lan` - Cloudflare tunnel on the rpi for services I want to access outside. I've it configured to require Google auth via cloudflare zero trust(free) The neat part of this setup is that when I access a service when I'm at home, it works as expected completely locally including https. If I try to access the service through the public internet, it will still work on the exact same domain and also have proper auth through cloudflare. This way I can access anything on the internet from my home server without worrying about security. Cloudflare tunnel also offers some other cool things like ssh on your browser(which again uses the previously mentioned Google auth) if you need it.
- layer8 2y agoIt only requires an entry in the local hosts file?