this post was submitted on 30 Jan 2025
295 points (99.3% liked)

Selfhosted

41581 readers
437 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

I think it's a good idea, everyone should be automating this anyway.

you are viewing a single comment's thread
view the rest of the comments
[–] wildbus8979@sh.itjust.works 0 points 1 day ago (1 children)

But then you have to distribute CAs to all the devices that will reach this service, and not all devices allow that.

[–] IsoKiero@sopuli.xyz 1 points 1 day ago (1 children)

True. And there's also a ton of devices around which don't trust LetsEncrypt either. There's always edge cases. For example, take a bit older photocopier and it's more than likely that it doesn't trust on anything on this planet anymore and there's no easy way to update CA lists even if the hardware itself is still perfectly functional.

That doesn't mean that your self-signed CA, in itself, would be technically any less secure than the most expensive Verisign certificate you can find. And yes, there's a ton of details and nuances here and there, but I'm not going to go trough every technical detail about how certificates work. I'm not an expert on that field by any stretch even if I do know a thing or two and there's plenty of material online to dig deep into the topic if you want to.

[–] wildbus8979@sh.itjust.works 0 points 1 day ago* (last edited 1 day ago)

I'm good. I know very well there are uses cases for a self signed cert. LE is still far more practical for 99% of use cases, even internally.