#TLS

2025-06-18

Running e-mail servers is always fun: as the time came to renew TLS certificate on one machine doing e-mail transmission (SMTP), came to know TLSA records are now supposed to be 3 1 1 (no more 3 0 1) :blobcateyes:

There is an added benefit of 3 (DANE-EE) 1 (subject public key) 1 (SHA2-256 hash digest) - if you do not rotate your private key to issue TLS certificate, you don't need to update the TLSA record - signature can be squeezed from key and certificate is not necessary at that point. If you do rotate private keys, this enables you to pre-create DNS records even before certificate is issued (given that you already generated keys) - that is really nice :blobcatthumbsup:

#serveradmin #email #dane #dns #tls #certificate #sha256

πŸ“‘ Flight Radar Mechelen πŸ‡§πŸ‡ͺRadarMechelen
2025-06-18

Flight:
ICAO code:
Callsign:
Operator: Brussels Airlines
Country: πŸ‡§πŸ‡ͺ
From: to
Speed: 545 kmh
Altitude: 1814 m
Distance: 0.6 km
Angle βˆ†: 70.5Β°
Direction ->: ENE
Track:
tinyurl.com/26xvmvd8
History:
radarbox.com/data/mode-s/44CE79
Seen: 365x

πŸ“‘ Flight Radar Mechelen πŸ‡§πŸ‡ͺRadarMechelen
2025-06-17

Flight:
Registration: OE-LNB
ICAO code:
Callsign:
Operator: European Air Transport Leipzig
Type: BOEING 757-236
Country: πŸ‡©πŸ‡ͺ
From: to
Speed: 469 kmh
Altitude: 1273 m
Distance: 1.3 km
Angle βˆ†: 44.7Β°
Direction ->: E
Track:
tinyurl.com/2dzb8n42
History:
radarbox.com/data/mode-s/440BBF
flightradar24.com/data/aircraf
Photos:
jetphotos.com/photo/keyword/OE
Seen: 13x

2025-06-17

What if #TLS used #PGP instead of #x509?

Above MaidstoneAboveMaidstone
2025-06-17

Flight:
ICAO code:
Registration: G-TAWB
Type: BOEING 737-800
Operator: Tui Airways Limited
Direction: 320Β° (Northwest)
Speed: 419.6 kmh
Altitude: 36625 ft
Category: Large

Route:
πŸ›«: Toulouse -
πŸ›¬: Birmingham -

Previously seen: 92 times

Track:
globe.adsb.fi/?icao=40665f

Photo by: Milan Witham
Link: hooks.geekyco.de/ps/40665f

2025-06-17

Hello, I’m hosting a #Vaultwarden server behind #Caddy 2.10 and made the following test:

Tuning Caddy to allow only #PQC curves:

	tls {
		curves x25519mlkem768
	}

Trying to connect with #Firefox Mac -> OK
Trying to connect with #Bitwarden #android client -> Fail

Without the #TLS tuning, the Bitwarden Android client will happily connect to the server.

Is it a problem with the Bitwarden Android client or with Android, or both?

aboveFRLaboveFRL
2025-06-17

ICAO: 48C2B9
Flt: RYR2LB -
First seen: 2025-06-17 19:03:39 CEST
Min Alt: 11264 m AGL
Min Dist: 1.92 km

globe.adsbexchange.com/?icao=4

πŸ“‘ Flight Radar Mechelen πŸ‡§πŸ‡ͺRadarMechelen
2025-06-17

Flight:
Registration: OO-SNO
ICAO code:
Callsign:
Operator: Brussels Airlines
Type: AIRBUS A320-216
Country: πŸ‡§πŸ‡ͺ
From: to
Speed: 538 kmh
Altitude: 2225 m
Distance: 1.1 km
Angle βˆ†: 63.1Β°
Direction ->: ENE
Track:
tinyurl.com/23kv6khe
History:
radarbox.com/data/mode-s/44CDCF
flightradar24.com/data/aircraf
Photos:
jetphotos.com/photo/keyword/OO
Seen: 514x

aboveFRLaboveFRL
2025-06-17

ICAO: 39856C
Flt: AFR69AR -
First seen: 2025-06-17 12:29:33 CEST
Min Alt: 10960 m AGL
Min Dist: 20.19 km

globe.adsbexchange.com/?icao=3

πŸ“‘ Flight Radar Mechelen πŸ‡§πŸ‡ͺRadarMechelen
2025-06-17

Flight:
Registration: OO-SSB
ICAO code:
Callsign:
Operator: Brussels Airlines
Type: AIRBUS A319-111
Country: πŸ‡§πŸ‡ͺ
From: to
Speed: 533 kmh
Altitude: 2286 m
Distance: 1.1 km
Angle βˆ†: 63.8Β°
Direction ->: ENE
Track:
tinyurl.com/2yuj5bgt
History:
radarbox.com/data/mode-s/44CE62
flightradar24.com/data/aircraf
Photos:
jetphotos.com/photo/keyword/OO
Seen: 414x

πŸ“‘ Flight Radar Mechelen πŸ‡§πŸ‡ͺRadarMechelen
2025-06-16

Flight:
Registration: D-ALET
ICAO code:
Callsign:
Operator: European Air Transport Leipzig
Type: BOEING 757-28A
Country: πŸ‡©πŸ‡ͺ
From: to
Speed: 491 kmh
Altitude: 1676 m
Distance: 0.8 km
Angle βˆ†: 64.4Β°
Direction ->: ENE
Track:
tinyurl.com/23vryrbb
History:
radarbox.com/data/mode-s/3C70B4
flightradar24.com/data/aircraf
Photos:
jetphotos.com/photo/keyword/D-
Seen: 89x

Felix Palmen :freebsd: :c64:zirias@bsd.cafe
2025-06-16

Next #swad release will still be a while. 😞

I *thought* I had the version with multiple #reactor #eventloop threads and quite some #lockfree stuff using #atomics finally crash free. I found that, while #valgrind doesn't help much, #clang's #thread #sanitizer is a very helpful debugging tool.

But I tested without #TLS (to be able to handle "massive load" which seemed necessary to trigger some of the more obscure data races). Also without the credential checkers that use child processes. Now I deployed the current state to my prod environment ... and saw a crash there (only after running a load test).

So, back to debugging. I hope the difference is not #TLS. This just doesn't work (for whatever reason) when enabling the address sanitizer, but I didn't check the thread sanitizer yet...

πŸ“‘ Flight Radar Mechelen πŸ‡§πŸ‡ͺRadarMechelen
2025-06-16

Flight:
Registration: OO-SNK
ICAO code:
Callsign:
Operator: Brussels Airlines
Type: AIRBUS A320-214
Country: πŸ‡§πŸ‡ͺ
From: to
Speed: 501 kmh
Altitude: 1570 m
Distance: 0.3 km
Angle βˆ†: 78.4Β°
Direction ->: ENE
Track:
tinyurl.com/2apdhjut
History:
radarbox.com/data/mode-s/44CDCB
flightradar24.com/data/aircraf
Photos:
jetphotos.com/photo/keyword/OO
Seen: 568x

aboveFRLaboveFRL
2025-06-16

ICAO: 398579
Flt: AFR69AR -
First seen: 2025-06-16 12:29:36 CEST
Min Alt: 10960 m AGL
Min Dist: 8.2 km

globe.adsbexchange.com/?icao=3

πŸ“‘ Flight Radar Mechelen πŸ‡§πŸ‡ͺRadarMechelen
2025-06-16

Flight:
ICAO code:
Callsign:
Operator: Brussels Airlines
Country: πŸ‡§πŸ‡ͺ
From: to
Speed: 519 kmh
Altitude: 1814 m
Distance: 1.6 km
Angle βˆ†: 48.4Β°
Direction ->: NE
Track:
tinyurl.com/27v6v5yu
History:
radarbox.com/data/mode-s/44CC44
Seen: 363x

aboveFRLaboveFRL
2025-06-16

ICAO: 4CA225
Flt: RYR2LB -
First seen: 2025-06-16 07:42:49 CEST
Min Alt: 11264 m AGL
Min Dist: 17.57 km

globe.adsbexchange.com/?icao=4

ΰ€°ΰ€žΰ₯ΰ€œΰ€Ώΰ€€ (Ranjit Mathew)rmathew
2025-06-16

I still call it β€œSSL”, even though I know TLS is what’s used these days πŸ€·πŸ½β€β™‚οΈ:

β€œSecurity Standards And Name Changes In The Browser Wars” [2024], Tim Dierks (tim.dierks.org/2014/05/securit).

Via HN: news.ycombinator.com/item?id=4

On Lobsters: lobste.rs/s/dygkfr/why_ssl_was

N-gated Hacker Newsngate
2025-06-16

In a thrilling tale of corporate warfare and digital acronyms, we learn that SSL's transformation to was less about security and more about scoring points in the browser slap-fight of the 90s. πŸ€ΊπŸ”’ and were so busy duking it out that they managed to rename a protocol instead of actually fixing it. πŸ™„βœ¨
tim.dierks.org/2014/05/securit

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst