ACME fail [rss]

Anonymous >30d ago #p4103 >>quote
site certificate just expired
Anonymous >30d ago #p4105 >>quote
agh gay!
.:-:. ## ADMIN >30d ago #p4107 >>quote
I would sign my own certs, but https is effectively under the control of a digital cartel so we have to deal with this stupid shit
segphault >30d ago #p4108 >>quote
Manjaro moment.
Anonymous >30d ago #p4109 >>quote
lol retard
Anonymous >30d ago #p4110 >>quote

https://digdeeper.club/articles/static.xhtml#ssl

You do not need to rely on a certificate authority to support encrypted connections - you can generate the cert yourself. This has some advantages in that you don't have to rely on a third party that can go down at any time, or just be hacked and compromised by "cybercriminals". You can have stronger encryption than the maximum offered by acme / Let's Encrypt (8192 vs 4096). You can have your cert be valid for whatever length of time you want to, instead of the puny month or 3 months or whatever of LE; you will never be canceled, either. And finally you can fill the data with funny stuff like this:

self_signed_cert.png
self_signed_cert.png

Showing the 'View certificate' window in Pale Moon for my diggy.club self-signed cert, with 'Dig Deeper Team' listed as the issuing organization

Compare to a Let's Encrypt-assigned one:

lets_encrypt_cert.png
lets_encrypt_cert.png

Showing the 'View certificate' window in Pale Moon for my digdeeper.club Let's Encrypt cert. The lack of fun stuff in the data is very obvious.

So what's the catch? Because there has to be one, right? There indeed is, and a very serious one. Namely that all mainstream browsers display a big scary warning when they encounter a self-signed cert. Like this:

cert_warning.png
cert_warning.png

Self-signed cert warning in Chrome-based browsers, claiming the connection is 'not private' and offering a way to 'get back to safety' by leaving the offending page

You can click Advanced and proceed to my site anyway, but every normie will retreat to his "safe" Google-shaped cage instead. So if you want any actual viewership, you can't rely on this at least unless you have another host with an "official" cert.

Attachments:
self_signed_cert.png (9.82 KB)
lets_encrypt_cert.png (10.3 KB)
cert_warning.png (4.53 KB)
.:-:. ## ADMIN >30d ago #p4111 >>quote
It just doesn't want to work. Yet another Linux moment where things just break for reasons unknown
.:-:. ## ADMIN >30d ago #p4112 >>quote
Ok, whatever. I'm going to use a self-signed cert and see how far this takes us then
admin ## ADMIN >30d ago #p4113 >>quote
>Someone could be trying to impersonate the site and you should not continue.

>Websites prove their identity via certificates. LibreWolf does not trust cy-x.net because its certificate issuer is >unknown, the certificate is self-signed, or the server is not sending the correct intermediate certificates.

>Error code: SEC_ERROR_UNKNOWN_ISSUER

admin@cy-x:~$ curl https://cy-x.net

>curl: (60) SSL certificate problem: unable to get local issuer certificate
>More details here: https://curl.se/docs/sslcerts.html
>curl failed to verify the legitimacy of the server and therefore could not establish a secure connection to it.
>To learn more about this situation and how to fix it, please visit the web page mentioned above.

>This Connection is Untrusted

>You have asked Pale Moon to connect securely to www.cy-x.net, but we can't confirm that your connection is secure.

>www.cy-x.net uses an invalid security certificate.
>The certificate is not trusted because the issuer certificate is unknown. The server might not be sending the appropriate intermediate certificates. An additional root certificate may need to be imported.
>(Error code: SEC_ERROR_UNKNOWN_ISSUER)

Fuck off! I'm not going to continue trying to mess around with this. I'm confident that everyone who actually uses this site on a weekly basis knows enough about technology to understand what a self-signed certificate is.
Anonymous >30d ago #p4114 >>quote
Fix the ssl you fucking retard
Replies: >>4115
.:-:. ## ADMIN >30d ago #p4115 >>quote
>>4114
It is now self-signed.
Anonymous >30d ago #p4116 >>quote
Yeah no shit. HTTPS broke open web standards and should have never been allowed to happen.
>just let me beg some authority figure to hand over a key so the browser doesn't spook the end user into thinking my website is malware
Replies: >>4138
Anonymous >30d ago #p4118 >>quote
>Community: 7 connected
>(IRC: 3 | XMPP: 3 | Mumble: 1)
That used to say 40 connected.
grim
Anonimus >30d ago #p4138 >>quote
>>4116
>>just let me beg some authority figure to hand over a key so the browser doesn't spook the end user into thinking my website is malware
central authorities are dumb but there hasnt really been a huge effort to decentralize it. we just sit in this shit and roll around whining. its also not that big of a problem, because the central authority just doesnt give a shit. letsencrypt might be a backdoor but it literally doesnt matter when 99% of people already have fifty backdoors on their machine anyway. admin just get acme.sh set up, its not hard. self-sign your onion or something

anyhow the forum has a lot of shitty fake advertising bots now. yay
Anonymous >30d ago #p4139 >>quote
Fix this


Secure site not available
Most likely, the website simply does not support HTTPS.

However, it's also possible that an attacker is involved. If you continue to the website, you should not enter any sensitive info. If you continue, HTTPS-Only mode will be turned off temporarily for the site.
Replies: >>4140
Anonimus >30d ago #p4140 >>quote
>>4139
just use http for now. admin is using a self-signed cert because autorenew fail
rave ## MOD >30d ago #p4143 >>quote
i'll solve this myself
rave ## MOD >30d ago #p4145 >>quote
fixed
rave ## MOD >30d ago #p4146 >>quote
>Community: 3 connected
>(IRC: 3 | XMPP: (offline) | Mumble: 0)
those are some really sexy stats
fuck you lets encrypt and your tiny expiration dates
NIGGER NIGGER NIGGER NIGGER NIGGER NIGGER NIGGER NIGGER NIGGER NIGGER NIGGER NIGGER >30d ago #p4147 >>quote
Based rave is not a faggot

[ reply ]