techhub.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A hub primarily for passionate technologists, but everyone is welcome

Administered by:

Server stats:

4.6K
active users

#tls

29 posts20 participants1 post today
Replied in thread

@jwildeboer : modern certificates are used for authentication only, not for secure connections.

OTOH, if you have no certainty that your software is communicating with the server you intended, a secure connection to it is pointless - but the connection remains secure.

Using TLS v1.3, the connection is even secured before the server is authenticated (if, after encrypting the connection, the authentication of the server fails, then the client should at least warn the user - if not immediately disconnect).

Yes, I know, these are boring details, but they are misunderstood way too often by people who SHOULD know how this works (I know you do, but please don't simplify things too much).

#TLS#https#X509

Flight: #BCS5AY
Registration: D-ALEU
ICAO code: #3C70B5
Callsign: #EUROTRANS
Operator: European Air Transport Leipzig
Type: BOEING 757-23N
Country: 🇩🇪
From: #TLS to #LEJ
Speed: 523 kmh
Altitude: 2134 m
Distance: 1.0 km
Angle ∆: 65.6°
Direction ->: ENE
Track:
tinyurl.com/29ah7xry
History:
radarbox.com/data/mode-s/3C70B5
flightradar24.com/data/aircraf
Photos:
jetphotos.com/photo/keyword/D-
Seen: 104x

tinyurl.comADS-B Exchange - track aircraft liveADS-B Exchange - track aircraft live - aircraft flight history

The suggestion that #dnssec is not important because we have #tls certs blows my mind. Domain validation (over DNS) is mandatory for every #x509 cert containing domain names (in the Web PKI ecosystem). If your DNS is compromised, your TLS cert is useless.

Hello, I’m a #newbiehere and I’m posting because I’d like to share something.

As an old IT guy, I want to share a script that makes life easier for (home) admins when a “curl” or “wget” fails during certificate (#SSL / #TLS) verification.
This doesn’t happen very often, so I always forgot what to do, when it did happen.

The script checks which certificates are missing and downloads them, so you can add them to your list of CAs (certification authorities) if needed. How to do this is explained in my accompanying documentation.

Maybe just take a look and see if it’s useful to you.

Of course it’s #opensource, described at github.com/himbeer-toni/UserSc, where you’ll also find a download link.

I’d be glad if it helps someone!

#opensource #programming #debian #linux #RasPi #sysAdmin #git #github #selfhost #selfhosted #selfhosting
#opensource #foss #homelab #homeserver #software #raspi #RasPi #sysAdmin #TLS #SSL #certificates
@digitalcourage
@linuxnews

Scripts for Linux user's ~/bin/ directory. Contribute to himbeer-toni/UserScripts development by creating an account on GitHub.
GitHubUserScripts/fetch-missing-ca.md at main · himbeer-toni/UserScriptsScripts for Linux user's ~/bin/ directory. Contribute to himbeer-toni/UserScripts development by creating an account on GitHub.

Hallo ich bin #neuhier und melde mich, weil etwas teilen möchte.

Als alter ITler möchte ich ein Skript teilen, dass dem (Home-)Admin das Leben erleichert, wenn wieder mal ein "curl" oder "wget" bei der Verifizierung eines Zertifikats (#SSL / #TLS) scheitert.
Das kommt nicht so oft vor, deswegen hatte ich immer vergessen was zu tun ist, wenn es mal wieder so weit war.

Das Script prüft welche Zertifikate fehlen, lädt sie herunter, so dass man sie ggf. in die Liste der CAs (certification authorities) aufnehmen kann. Wie das geht, steht in meiner dazugehörigen Doku.

Vielleicht einfach mal sehen, ob ihr es brauchen könnt.

Natürlich #opensource, beschrieben auf github.com/himbeer-toni/UserSc, da wäre dann auch ein Downloadlink.

Würde mich freuen, wenn es jemandem hilft!

#opensource #programming #debian #linux #RasPi #sysAdmin #git #github #selfhost #selfhosted #selfhosting
#opensource #foss #homelab #homeserver #software #raspi #RasPi #sysAdmin #TLS #SSL #certificates
@digitalcourage
@linuxnews

Scripts for Linux user's ~/bin/ directory. Contribute to himbeer-toni/UserScripts development by creating an account on GitHub.
GitHubUserScripts/fetch-missing-ca.md at main · himbeer-toni/UserScriptsScripts for Linux user's ~/bin/ directory. Contribute to himbeer-toni/UserScripts development by creating an account on GitHub.