Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The most annoying thing about it is the short expiry time.

I'm using a wildcard certificate so my internal services can be accessed without resorting to installing a self-singed CA cert on all my devices. I've set up a script to renew it every month but unfortunately distributing the resulting certificate to all internal services is proving difficult. There is no simple way to update the cert in my managed switches or the IPMI interface on my servers without resorting to custom scripts to upload it via the web interface.

If it was a once-a-year job I could do it manually, but these certificates need to be regularly replaced which makes it a PITA.



Another option for e.g. network devices is to run your own CA, i.e. issue your own root certificate.


BuyPass uses ACME to issue free certificates that expire in 180 days: https://www.buypass.com/ssl/products/acme




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: