Comment on Do you run a private CA? Could you tell me about your certificate setup if you do?

<- View Parent
MigratingtoLemmy@lemmy.world ⁨6⁩ ⁨months⁩ ago

Thank you. Could you explain a bit more about your setup and the aspects I should be looking at? Specifically:

Thanks for the mention, I was looking at a script to automate certificate generation and revocation too.

Since we’re talking about reverse-proxies, I’ll mention that I plan to run an instance of HAProxy per podman pod so that I terminate my encrypted traffic inside the pod and exclusively route unencrypted traffic through local host inside the pod. I’m doing this because I do not want to see any unencrypted traffic in my network. Of course, this is some more overhead but I think this is doable. I got this idea from another post I made a while back. Of course, that means that every pod on my network (hosting an HAProxy instance) will be given a distinct subdomain, and I will be producing certificates for specific subdomains, instead of using a wildcard.

Thanks, I’ll be sure to document my progress as I go.

source
Sort:hotnewtop