Post B6CLRpMGdpHdF7zuc4 by jima@mspsocial.net
(DIR) More posts by jima@mspsocial.net
(DIR) Post #B66QlCP6W2OJ2hcaMS by owen@mastodon.transneptune.net
0 likes, 1 repeats
Do you want to put a web page on a .local address to do something cool for your household or club? Here's the list of browser features that browser vendors have decided you're just not fuckin' allowed to use. https://developer.mozilla.org/en-US/docs/Web/Security/Defenses/Secure_Contexts/features_restricted_to_secure_contextsSome random site halfway around the world, served over https with a robo-verified certificate, is allowed, though, so take some comfort in that.
(DIR) Post #B66QlDCNYpo3VWfwAK by owen@mastodon.transneptune.net
0 likes, 0 repeats
There's a discussion thread about allowing RFC 1918 addresses and their ip6 equivalents to participate in secure contexts at https://github.com/w3c/webappsec-secure-contexts/issues/60 . It is _eight years_ old without resolution.I can't find any discussion at all on allowing the user to designate certain origins as secure contexts. Maybe that's a thing for some browsers.
(DIR) Post #B66QlDcbzIn2oswt3Q by owen@mastodon.transneptune.net
0 likes, 0 repeats
The recommendation in that thread is to run a private CA for your LAN. Anyone who has experience doing that outside of a managed (i.e., corporate) network will tell you how hilariously useless that advice is.
(DIR) Post #B66R4f8VuhIZem8sZk by ryanc@infosec.exchange
0 likes, 0 repeats
@owen I use acme-dns authorized subdomain certificates on my lab, this is nearly as unreasonable as running a CA for my home network. And I have run one on a corporate network.
(DIR) Post #B66R4fTQew1qhdvaAy by azonenberg@ioc.exchange
0 likes, 0 repeats
@ryanc @owen I mean I have my own local CA with two different intermediate CAs, but I also run my own DNS.And I need the CA to issue client certificates to VPN clients (I have a ban on password authentication, to the extent supported by the service, for anything network reachable). Once you have that infrastructure in place also issuing your own HTTPS certs is straightforward enough.But it's certainly not something the average person wants to deal with.
(DIR) Post #B66R9dVXOciw3NHcDw by ryanc@infosec.exchange
0 likes, 0 repeats
@azonenberg @owen I run my own mail server, and the Wi-Fi at home, that is my limit.
(DIR) Post #B66RKHMU4hdsYQ7hk8 by azonenberg@ioc.exchange
0 likes, 0 repeats
@ryanc @owen I don't run my own mail, mostly because I'm on a DOCSIS pipe that (despite being a static) is probably part of a larger netblock that's on spam blacklists.At some point maybe I'll look at getting a box in a colo or something to do that but right now I don't have time to deal with the hassle of actually making my mail be delivered.I do want to move to a managed mail host that is anything-but-ms365 though, since my previous mail host rolled up their in house operation and turned into a 365 reseller
(DIR) Post #B66RgrArbaCbznSC00 by azonenberg@ioc.exchange
0 likes, 0 repeats
@ryanc @owen but like, for scale my internal BIND zone file has 177 A records in it, split across 20 subnets. This is not a small network so an internal CA is a tiny amount of management overhead compared to everything else.
(DIR) Post #B6AWLcmHDG5RfRUKFk by lanodan@queer.hacktivis.me
0 likes, 0 repeats
@dalias @jima @ryanc @owen Well the challenge allows to delegate to another zone/nameserver (what I do here), but it's probably not the most typical setup.
(DIR) Post #B6AWVxBEDCK3qA5I00 by jima@mspsocial.net
1 likes, 0 repeats
@lanodan @dalias @ryanc @owen It's always so nice to meet other DNS weirdos. 🥰
(DIR) Post #B6CLQc2qecBbfBKqQq by nowster@fedi.nowster.me.uk
1 likes, 0 repeats
@jima@mspsocial.net @lanodan@queer.hacktivis.me @dalias@hachyderm.io @ryanc@infosec.exchange @owen@mastodon.transneptune.net Is the collective noun of DNS weirdos a delegation or a resolution?
(DIR) Post #B6CLRpMGdpHdF7zuc4 by jima@mspsocial.net
1 likes, 0 repeats
@nowster @lanodan @dalias @ryanc @owen My vote is for "delegation." Good question!