photog.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A place for your photos and banter. Photog first is our motto Please refer to the site rules before posting.

Administered by:

Server stats:

246
active users

#ssl

1 post1 participant0 posts today

Okay I've used up all other options, so now it's #FollowerPower and #FediMagic :

Would someone here be able to help me fix my broken #Yunohost instance? I've been without email for several weeks now 😓

All apps and admin interface work without problems, but #Dovecot fails to start with a cryptic #SSL error. I've tried the forum of course but so far without success.

Happy to share logs and all. Thanks a million! 🙏

Hallo ich bin #neuhier und melde mich, weil etwas teilen möchte.

Als alter ITler möchte ich ein Skript teilen, dass dem (Home-)Admin das Leben erleichert, wenn wieder mal ein "curl" oder "wget" bei der Verifizierung eines Zertifikats (#SSL / #TLS) scheitert.
Das kommt nicht so oft vor, deswegen hatte ich immer vergessen was zu tun ist, wenn es mal wieder so weit war.

Das Script prüft welche Zertifikate fehlen, lädt sie herunter, so dass man sie ggf. in die Liste der CAs (certification authorities) aufnehmen kann. Wie das geht, steht in meiner dazugehörigen Doku.

Vielleicht einfach mal sehen, ob ihr es brauchen könnt.

Natürlich #opensource, beschrieben auf github.com/himbeer-toni/UserSc, da wäre dann auch ein Downloadlink.

Würde mich freuen, wenn es jemandem hilft!

#opensource #programming #debian #linux #RasPi #sysAdmin #git #github #selfhost #selfhosted #selfhosting
#opensource #foss #homelab #homeserver #software #raspi #RasPi #sysAdmin #TLS #SSL #certificates
@digitalcourage
@linuxnews

Scripts for Linux user's ~/bin/ directory. Contribute to himbeer-toni/UserScripts development by creating an account on GitHub.
GitHubUserScripts/fetch-missing-ca.md at main · himbeer-toni/UserScriptsScripts for Linux user's ~/bin/ directory. Contribute to himbeer-toni/UserScripts development by creating an account on GitHub.
Replied in thread

@drscriptt granted, we all want 203.0.113.1¹ to have #SSL / #TLS (even if it's just @letsencrypt ) work than not work or have no #encryption.

  • That is not up for debate!

I just think that this will reward previously standards-violating behaviours when i.e. Xavier Sample Solutions don't get nudged to use i.e. api.solutions.example² but can just use their IP addresses.

¹ Example as per RFC5737
² Example as per RFC2606

1.1.1.11.1.1.1 — The free app that makes your Internet faster.Install the free app that makes your phone’s Internet more fast, private, and reliable.

It seems I need to restart my server (Ubuntu) after I renew my Certbot cerificate in order for the update to be recognised. Probably coud just restart Nginx I expect, but anyway... any clever peeps on here that know if I can actually get the renewed certificate (and its validity dates) served up without any downtime? #certbot #ssl #server #linux

Let's #Encrypt rolls out free IP address #certificates • The Register

Let's Encrypt, a #CertificateAuthority (CA) known for its free TLS/SSL certificates, has begun issuing digital certificates for IP addresses.

It's not the first CA to do so. #PositiveSSL , #Sectigo, and #GeoTrust all offer TLS/SSL certificates for use with IP addresses, at prices ranging from $40 to $90 or so annually. But Let's Encrypt does so at no cost.
#security #tls #ssl #privacy

theregister.com/2025/07/03/let

The Register · Let's Encrypt rolls out free security certs for IP addressesBy Thomas Claburn

🍝 Parlando di cose migliori: ho contribuito al progetto della #Biblioteca dei Semi Narrativi di @alxd : ora potete consultare tutte le voci anche in italiano!

storyseedlibrary.org/it

Se avete bisogno di #illustrazioni #solarpunk per i vostri progetti, la #SSL è piena di opere fantastiche, tutte copyleft! Pescatene a piene mani e, se conoscete qualche altra lingua, fatevi avanti e traducete! È questione di qualche pomeriggio 😄

Biblioteca dei Semi NarrativiBenvenuti alla Biblioteca dei Semi Narrativi!Una biblioteca di opere e semi narrativi Solarpunk per aiutarvi a immaginare un futuro climatico migliore!

DNSSEC is a big deal. It’s complex, but it doesn’t have to be boring. So we figured, why not let a taco explain it? We’re demystifying DNSSEC in the most entertaining way possible, complete with quirky jokes and characters. We love sharing our knowledge of all things #DNS, #SSL certs, and #DNSSEC, and we hope you enjoy this interactive exploration of How DNSSEC Works!

howdnssec.works/

howdnssec.worksHow DNSSEC worksLearn why DNS needs security through tacos, crabs, and cryptographic laughs. How DNSSEC Works turns complex internet plumbing into an illustrated adventure.

In case you haven't seen it yet, check out the analysis of the devastating state of [mostly] modern #OpenSSL by members of haproxy at haproxy.com/blog/state-of-ssl- - hard to imagine such massive performance regressions getting into mainline linux distributions unnoticed by the distributors. #linux #ssl

HAProxy TechnologiesThe State of SSL StacksThe SSL landscape has shifted dramatically. In this paper, we examine OpenSSL 3.x, BoringSSL, LibreSSL, WolfSSL, and AWS-LC with HAProxy.

Tech vocablurary question:

Are you seeing people still referring to "SSL” as the most natural thing, or have we finally moved on to calling TLS simply "TLS”?

TLS was introduced more than 25 years ago as a SSL replacement. SSL v3 was deprecated 10 years ago. Isn't it time we also deprecate the use of the term SSL?

My opinion is that we're looking less professional by continuing to deadname TLS.

Thankful for any input and observations from your part of the IT / networking fields.

#ssl#tls#networking

digicert.com/blog/tls-certific

The CA/Browser Forum has officially voted to amend the TLS Baseline Requirements to set a schedule for shortening both the lifetime of TLS certificates.

The maximum certificate lifetime is going down:

- As of March 15, 2026, the maximum lifetime for a TLS certificate will be 200 days.
- As of March 15, 2027, the maximum lifetime for a TLS certificate will be 100 days.
- As of March 15, 2029, the maximum lifetime for a TLS certificate will be 47 days.

www.digicert.comTLS Certificate Lifetimes Will Officially Reduce to 47 DaysThe CA/Browser Forum has officially voted to amend the TLS Baseline Requirements to set a schedule for shortening both the lifetime of TLS certificates.