Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #264712
| From | Pocket <pocket@columbus.rr.com> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: update-ca-certificates |
| Date | 2023-12-14 03:00 +0100 |
| Message-ID | <HKJb3-dpY4-3@gated-at.bofh.it> (permalink) |
| References | <HKIeZ-dpqU-1@gated-at.bofh.it> <HKIRI-dpRR-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 12/13/23 20:34, jeremy ardley wrote: > > On 14/12/23 08:54, Pocket wrote: >> >> I have just finished writing some scripts to generate certs for my >> email server and nginx server. >> >> The scripts allow me to become my own CA. > > > You don't have to be your own CA. It's very easy to use letsencrypt to > generate valid certificates for hosts even if they are not directly > connected to the internet. I don't want to use letsencrypt, that is a non-starter > > In my case I use letsencrypt for certificates for nginx, dovecot, and > postfix. They all use the same certificates maintained by > letsencrypt/certbot by linking to it in their configuration, > > letsencrypt/certbot manages all the certificates and necessary > renewals using cron jobs at regular intervals. Which is why I don't want to use it. Don't want to install any more packages or update cron (I have not added cron jobs). > > The situations where you still need to be your own CA are for > applications like OpenVPN and certificates for ssh servers and clients On my network I want to control the certs used. -- It's not easy to be me
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 02:00 +0100
Re: update-ca-certificates Roberto C. Sánchez <roberto@debian.org> - 2023-12-14 02:30 +0100
Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 03:00 +0100
Re: update-ca-certificates jeremy ardley <jeremy.ardley@gmail.com> - 2023-12-14 02:40 +0100
Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 03:00 +0100
Re: update-ca-certificates Charles Curley <charlescurley@charlescurley.com> - 2023-12-14 04:00 +0100
Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 04:10 +0100
letsencrypt certs for disconnected hosts (Was Re: update-ca-certificates) Andy Smith <andy@strugglers.net> - 2023-12-14 13:20 +0100
Re: update-ca-certificates Jeffrey Walton <noloader@gmail.com> - 2023-12-14 03:50 +0100
Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 04:00 +0100
Re: update-ca-certificates Jeffrey Walton <noloader@gmail.com> - 2023-12-14 05:00 +0100
Re: update-ca-certificates Jeffrey Walton <noloader@gmail.com> - 2023-12-14 12:40 +0100
Re: update-ca-certificates Henning Follmann <hfollmann@itcfollmann.com> - 2023-12-14 14:20 +0100
Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 14:50 +0100
Re: update-ca-certificates Linux-Fan <Ma_Sys.ma@web.de> - 2023-12-14 20:30 +0100
Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 20:40 +0100
Re: update-ca-certificates Linux-Fan <Ma_Sys.ma@web.de> - 2023-12-14 21:00 +0100
csiph-web