4 ms·
I actually don’t have a problem with the SSL changes as they specifically pertain to http servers – it’s largely a dived problem with automated solutions compat
by ComputerGuru 1y ago
I actually don’t have a problem with the SSL changes as they specifically pertain to http servers – it’s largely a dived problem with automated solutions compatible with all the major players on most fronts.
But certs and every other context have become neigh impossible except in enterprise settings with your own CA and cert servers. From things like printers and network appliances to entirely non-http applications like VPN (StrongSwan and OpenVPN both have/support TLS with signed SSL certs, but place very different constraints on how those work in practice and what identities are supported, how or if wildcards work, etc).
Very little attention has been paid to non-general purpose and non-http contexts as things currently stand.
- DougN7 1y agoThe last time I looked, if you ran your HTTPS service on anything other than port 443 LetsEncrypt was not for you. Maybe that’s built into ACME?
- OptionOfT 1y agoYou can get LetsEncrypt certificates for endpoints that aren't publically accessible through the DNS-01 challenge.
- mdaniel 1y agoI can't tell if it's a typo but HTTP-01 would contact your webserver on :80 in order to successfully retrieve a very, very, very specific ACME path and does not care at all what you do with your issued TLS afterward, including what port you run it upon Also, I know firsthand that the DNS Validator also works perfectly fine, no http check required
- DougN7 1y agoThat’s right. So a private server hosted on something other than port 80 (like port 81 in my case) is where you’re out of luck :(