I’ve never heard it called anything but mTLS. :shrug:
- 0 Posts
- 27 Comments
False@lemmy.worldto
Selfhosted@lemmy.world•reverse proxy over vpn without docker?English
3·1 month agoDocker is fine for turnkey applications. Mounting external storage that persists across containers is a feature that enables that pattern.
Running Docker in a VM is also fine and has potential advantages. However I agree that it’s probably overly complex for many people.
I’m confused what you’re trying to accomplish here. Are you trying to make it look like the traffic is coming from your VPS for some reason? Nginx (amongst others) can reverse proxy tcp traffic.
False@lemmy.worldto
Selfhosted@lemmy.world•In what way am I the product when using CloudFlare's free tier?English
751·1 month agoThis is basically “the first hit is free”
False@lemmy.worldto
Selfhosted@lemmy.world•Guarding My Git Forge Against AI ScrapersEnglish
21·2 months agodeleted by creator
False@lemmy.worldto
Selfhosted@lemmy.world•Decreasing Certificate Lifetimes to 45 DaysEnglish
11·2 months agoYeah you can still do a lot of damage in a few hours, but 45 days is a meaningful reduction in exposure time from year+
False@lemmy.worldto
Selfhosted@lemmy.world•Decreasing Certificate Lifetimes to 45 DaysEnglish
5·2 months agoThat’s a complaint about those phones not PKI in general then. Though it’s surprising their enterprise support won’t let you since that is (or was) a fairly common thing for businesses to do.
False@lemmy.worldto
Selfhosted@lemmy.world•Decreasing Certificate Lifetimes to 45 DaysEnglish
6·2 months agoIsn’t this just CRL in reverse? And CRL sucks or we wouldn’t be having this discussion. Part of the point of cryptographically signing a cert is so you don’t have to do this if you trust the issuer.
Cryptography already makes it infeasible for a malicious actor to create a fake cert. The much more common attack vector is having a legitimate cert’s private key compromised.
False@lemmy.worldto
Selfhosted@lemmy.world•Decreasing Certificate Lifetimes to 45 DaysEnglish
10·2 months agoBrowsers are only a (large) fraction of SSL traffic.
False@lemmy.worldto
Ask Lemmy@lemmy.world•Would the movie Donnie Darko be better without Jake Gyllenhaal?
10·3 months agoI thought it was fine with him?
The term to look for is out of band management. Typically this will provide serial/console access to a device, and can often perform actions like power cycling. A lot of server hardware has this built in (eg idrac for Dell, IPMI generically). Some users will have a separate oobm network for remotely accessing/managing everything else.
False@lemmy.worldto
Programmer Humor@programming.dev•Context: Docker bypasses all UFW firewall rules
21·5 months agoExplicitly binding certain ports to the container has a similar effect, no?
False@lemmy.worldto
Selfhosted@lemmy.world•Tailscale addressing concerns over potential enshittification of the platformEnglish
254·7 months agoIt amazes me that so many people obsessed about self hosting everything use this service - really asking for it.
False@lemmy.worldto
Selfhosted@lemmy.world•How to use GPUs over multiple computers for local AI?English
71·10 months agoI didn’t say you were, I said you were asking about a topic that enters that area.
False@lemmy.worldto
Selfhosted@lemmy.world•How to use GPUs over multiple computers for local AI?English
72·10 months agoYou’re entering the realm of enterprise AI horizontal scaling which is $$$$
False@lemmy.worldto
Selfhosted@lemmy.world•How to use GPUs over multiple computers for local AI?English
1·10 months agodeleted by creator
False@lemmy.worldto
Ask Lemmy@lemmy.world•How much weight are the 8-10 humans at tier 2.5 carrying?
9·10 months agoMFW I trained for years to be the best athlete I can be
MFW my role is to just sit on the ground
False@lemmy.worldto
Selfhosted@lemmy.world•Some local LLMs tested on an average gaming PCEnglish
16·10 months agoI thought I had a lot of RAM with 64
False@lemmy.worldto
Selfhosted@lemmy.world•How do I use HTTPS on a private LAN without self-signed certs?English
3·10 months agoImport it into the trust store in the browser/OS. It should be the same (or very similar) operation for a self-signed cert and a CA that isn’t subordinate to the standard internet root CAs.
If you can’t import your own root CA cert then you’re probably screwed on both fronts and are going to have to use certs issued by a public CA that’s subordinate to a commonly trusted root CA.
My point here is that there’s little distinguishing a self-signed cert and a cert issued by your own private CA for most people that are self-hosting.
False@lemmy.worldto
Selfhosted@lemmy.world•How do I use HTTPS on a private LAN without self-signed certs?English
2·10 months agoTrust the self signed cert. Works similarly to trusting a CA.
I had it working on a 5700xt a couple years ago