this post was submitted on 16 Oct 2024
192 points (91.4% liked)

Technology

59374 readers
7248 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 9 points 4 weeks ago (9 children)

This is the one case where I'd make an exception. I read through the threads, it got particularly heated.

[–] [email protected] 7 points 4 weeks ago (8 children)

As someone who creates custom domain name applications, FUCK THEM WITH A PINEAPPLE SPIKY SIDE FIRST. This problem is on par with timezones for needless complexity and communication disasters. Companys and advertisers are now adding man in the middle certs for additional data collection/visibility. If the ciphers not cracked, changing the certs exposes significantly more failure, than letting one get a little stale.
Sysadmin used slam! It's super effective!

[–] [email protected] 3 points 4 weeks ago (4 children)

Why not just autorenew on a schedule?

I use Lets Encrypt, and my certs get renewed automatically without me thinking about it.

[–] [email protected] 3 points 4 weeks ago (1 children)

Mostly customer provided certs, high end clients make all kinds of stupid requests like the aforementioned man-in-the-middle chain sniffers, clients that refuse DNS validation, clients that require alternate domains to be updated regularly. Management is fine for mywebsite.com, but how are you solving an EV on the spoofed root prod domain, with an sso cert chain for lower environments on internal traffic that is originally provided by a client? And do you want the cs reps emailing each other your root cert and (mistakingly) the key? I've been given since SCARY keys by clueless support engineers. I don't want to do this every 3 months.

[–] [email protected] 2 points 4 weeks ago (1 children)

Sounds like a change in company policy, because AFAIK, there's no good reason for pretty much any of that.

[–] [email protected] 2 points 4 weeks ago (1 children)

Sounds like you don't do contact negotiations, if someone will pay 2 million to appear on their root domain, you'll sit down and figure it out for a couple hours.

[–] [email protected] 1 points 4 weeks ago

Yes, I don't, and I would honestly like to understand what use-case these customers are trying to solve. Because there's a very good chance that they can get their preferred outcomes with a lot less manual work.

load more comments (2 replies)
load more comments (5 replies)
load more comments (5 replies)