Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #264712

Re: update-ca-certificates

From Pocket <pocket@columbus.rr.com>
Newsgroups linux.debian.user
Subject Re: update-ca-certificates
Date 2023-12-14 03:00 +0100
Message-ID <HKJb3-dpY4-3@gated-at.bofh.it> (permalink)
References <HKIeZ-dpqU-1@gated-at.bofh.it> <HKIRI-dpRR-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 12/13/23 20:34, jeremy ardley wrote:
>
> On 14/12/23 08:54, Pocket wrote:
>>
>> I have just finished writing some scripts to generate certs for my 
>> email server and nginx server.
>>
>> The scripts allow me to become my own CA. 
>
>
> You don't have to be your own CA. It's very easy to use letsencrypt to 
> generate valid certificates for hosts even if they are not directly 
> connected to the internet.


I don't want to use letsencrypt, that is a non-starter


>
> In my case I use letsencrypt for certificates for nginx, dovecot, and 
> postfix. They all use the same certificates maintained by 
> letsencrypt/certbot by linking to it in their configuration,
>
> letsencrypt/certbot manages all the certificates and necessary 
> renewals using cron jobs at regular intervals.


Which is why I don't want to use it.

Don't want to install any more packages or update cron (I have not added 
cron jobs).


>
> The situations where you still need to be your own CA are for 
> applications like OpenVPN and certificates for ssh servers and clients

On my network I want to control the certs used.

-- 
It's not easy to be me

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 02:00 +0100
  Re: update-ca-certificates Roberto C. Sánchez <roberto@debian.org> - 2023-12-14 02:30 +0100
    Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 03:00 +0100
  Re: update-ca-certificates jeremy ardley <jeremy.ardley@gmail.com> - 2023-12-14 02:40 +0100
    Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 03:00 +0100
    Re: update-ca-certificates Charles Curley <charlescurley@charlescurley.com> - 2023-12-14 04:00 +0100
      Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 04:10 +0100
      letsencrypt certs for disconnected hosts (Was Re:  update-ca-certificates) Andy Smith <andy@strugglers.net> - 2023-12-14 13:20 +0100
  Re: update-ca-certificates Jeffrey Walton <noloader@gmail.com> - 2023-12-14 03:50 +0100
    Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 04:00 +0100
      Re: update-ca-certificates Jeffrey Walton <noloader@gmail.com> - 2023-12-14 05:00 +0100
        Re: update-ca-certificates Jeffrey Walton <noloader@gmail.com> - 2023-12-14 12:40 +0100
    Re: update-ca-certificates Henning Follmann <hfollmann@itcfollmann.com> - 2023-12-14 14:20 +0100
      Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 14:50 +0100
        Re: update-ca-certificates Linux-Fan <Ma_Sys.ma@web.de> - 2023-12-14 20:30 +0100
          Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 20:40 +0100
            Re: update-ca-certificates Linux-Fan <Ma_Sys.ma@web.de> - 2023-12-14 21:00 +0100

csiph-web