Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
adrukh
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
adrukh
11mo ago
I hope the fact I wrote and posted this on a weekend isn't lost on you! :)
2.
▲
The Weekend SSL Certificate Expiration Pattern
(haveibeenexpired.com)
6 points
by
adrukh
11mo ago
|
2 comments
3.
▲
by
adrukh
5y ago
I'm not keen on adding username/password registration, but I do have additional SSO flows behind the scenes: GitHub - https://www.haveibeenexpired.com/auth/github Windows Live - https://www.haveibe
4.
▲
by
adrukh
5y ago
Thanks for this feedback! I have now changed this to include only logos of companies with whom I am directly involved, who are actively using my service to monitor their SSL certificates, and who have agreed to have their logos appear on my
5.
▲
by
adrukh
5y ago
Oh wow, do tell me more please! Indeed, I wanted to spare myself from implementing more detailed registration, but mainly wanted to keep the user from more steps in the registration process. What would be an acceptable sign-in method for yo
6.
▲
by
adrukh
5y ago
Hmmm I didn't add anything specific for IPv6, could be something related to Heroku (where my app is hosted). Can you share an IPv6-only host with me so that I can run some tests?
7.
▲
by
adrukh
5y ago
:hugging_face:
8.
▲
by
adrukh
5y ago
:wave: I'm an Israeli citizen, and this app is basically mine. No company behind it. I hear what you are saying about the credibility hit I'm taking with showing logos like this. Will think what to do about it!
9.
▲
by
adrukh
5y ago
Thank you, this is quite insightful! > I also found no information on what happens if the Webhook endpoint is not reachable. When setting a webhook, the app checks it for validity (you get a nice 'hooray, it works!' message pos
10.
▲
by
adrukh
5y ago
Ah, very nice! Not sure it'll work, but you can specify any port for a website you want to check manually. See if https://www.haveibeenexpired.com/ssl/app.srsc.ru:8443 (replace the host name and port with what you
11.
▲
by
adrukh
5y ago
Yeah, that won't fly on my app right now because I only want it to notify you about an SSL cert that is both being served by some publicly-reachable host AND is about to expire soon. A cert that was issued, found on CT, and expires tom
12.
▲
by
adrukh
5y ago
Absolutely! But... my app automatically finds new relevant hosts and adds them to the monitoring cycles, needing 0 intervention after you tell it which domains interest you. Not saying it's everyone's need, but I'm here for t
13.
▲
by
adrukh
5y ago
You are totally correct! But another way in which email is 'expensive' is troubleshooting deliverability issues, handling bounces, unsubscribes, landing in the 'promotions' tab of your gmail inbox, etc. Webhooks are... e
14.
▲
by
adrukh
5y ago
The 'companies we monitor' are just that - domains that I added to my own user in this app. Yes, it can appear shady, as if I was trying to hint that these juggernauts are my clients. They are not :) But hey, public servers are pu
15.
▲
by
adrukh
5y ago
This is an amazing input for me, thank you very much! I used a canned policy, and may have totally mixed a couple of things up. Will review and change it :)
16.
▲
by
adrukh
5y ago
Thanks! The thing here is that you don't have to keep updating the app with every new host you create that needs to be monitored. CT allows me to detect newly issued certs in your domain, and start monitoring them without manual work o
17.
▲
by
adrukh
5y ago
Sorry, wasn't clear - I want to get the minimal input from my users, and right now all I have is the google email. Totally agree that to capture the audience that relies on email, asking for a mailing list for notifications is much bet
18.
▲
by
adrukh
5y ago
:heart_eyes:
19.
▲
by
adrukh
5y ago
> Is expiration monitoring done solely through certificate transparency logs or also by connecting to the host? For every detected host, the app periodically performs an SSL handshake (HTTPS only), and checks for the expiration of the se
20.
▲
by
adrukh
5y ago
Totally fair! In a market that is very saturated with feature-rich services, I want to do something narrow, and address a specific need. It makes it easier for me to rely on certificate transparency, as I'm adding new hosts automatical
21.
▲
by
adrukh
5y ago
I'll look into those, thanks for the heads-up! Off the cuff answer - I want to be very focused on a specific use-case - a live cert that is about to expire. This allows me to be very greedy on the automatic addition of new hosts, witho
22.
▲
by
adrukh
5y ago
I totally admit the tweak here! Of course these giants don't rely on my service, and have better tools. But hey, I do point out an upcoming glitch here and there - https://twitter.com/haveibeenexpir1/status/14
23.
▲
by
adrukh
5y ago
This is intentional (although may change in the future), for one main reason - I believe that email is personal, and webhooks are a much better way to notify _teams_. Strongly believe that SSL expiration handling is a team effort! Thanks fo
24.
▲
by
adrukh
5y ago
A side project of mine for your viewing pleasure! Secret sauce - it uses https://certificate.transparency.dev/ to crawl your domain and automatically add new hosts for monitoring.
25.
▲
Show HN: Never have an SSL certificate expire again
(haveibeenexpired.com)
40 points
by
adrukh
5y ago
|
71 comments