






















We created a fake CA that can solve the Let's Encrypt challenges and provision the non-wildcard certificates to the local network. It's ugly, but it works reasonably well. It has its own downside of exposing all the internal infrastructure in CT logs.
A proper solution is constrained CA certificates. This has been supported by X509 for _ages_ and it's a mandatory X509 extension for browsers since 2019.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。