haroldfinch
@haroldfinch@feddit.nl
This is a mystery you don’t want to solve.
- Comment on Anyone using 6-day certs yet? 3 days ago:
I had no idea “single use certificates” were a thing. It makes sense, although from my personal perspective I have always worked with managed identities and privilege escalation.
I have almost no internet facing services, although the two I have I might swap for the short lived variants. As you said, risk of misuse due to compromise goes down so that makes sense.
For my other services, they are all running on HTTPS, but only available internally over LAN or VPN, all with isolated VLANs sort of like a Hub Spoke model. The two certs that are internet facing are basically for getting access to my VPN. Might swap the internal services to short lived anyway if the automation works well, as I said before, it’s fully automated anyway.
- Comment on Anyone using 6-day certs yet? 4 days ago:
Thabknyou for sharing. I had missed the announcement, so pleased to know the option is available.
I have fully automated the creation and renewal of my certs and have just short of 50 certs that I manage in total. Every single one automated using NixOS / ACME / lego.
Technically I could easily implement this, just have to switch my config.
Honest question, are there any particular security benefits to this (especially for a home lab)?
I can understand the short lived time span further reduces risk of compromise, yet the existing time span is already “much shorter than traditional certificates”. Does it have a substantial impact on our security posture?
- Comment on Auth apps 2 months ago:
It has a modest UI for end-users to handle self-service scenarios, and an app portal for OpenID Connect configured applications.
The backend is fully CLI based.
It is very robust and performant, built on Rust.
Yet very much in active development, so do not expect full parity with commercial alternatives at a feature level.
I run it to provision users for my home Linux devices and it supports offline login, my Homelab servers, and my self-hosted web applications through OIDC.
A nice ‘one stop shop’ for my purposes.