#certificates

Linuxiaclinuxiac
2026-02-22

With DNS-PERSIST-01, Let’s Encrypt users can validate their domains without having to update DNS records every time they issue or renew a certificate.
linuxiac.com/lets-encrypt-intr

With DNS-PERSIST-01, Let’s Encrypt users can validate their domains without having to update DNS records every time they issue or renew a certificate.
Sami Lehtinensl@pleroma.envs.net
2026-02-22

ZeroSSL a kind request, supporting DNS-PERSIST-01 validation method would be just awesome! - Thanks

#ZeroSSL #EuropeanAlternatives #TLS #Validation #Certificates #LetsEncrypt

Inautiloinautilo
2026-02-20


DNS-PERSIST-01 · A new model for DNS-based challenge validation ilo.im/16aqtz

_____

2026-02-16

Problems with importing Firewall CA Certificate #2204 #vpn #ssl #certificates #github

askubuntu.com/q/1564035/612

2026-02-14

Do you hate #passwords as much as I do?
Can't we have public key #authentication everywhere? Like in my #email client?

Yes we can! Without #authkeys!

Because #TLS supports not just #server side #certificates , but also the client can be verified.

My #Dovecot now logs me in without a password :D I just need to possess a valid (unlocked) private key. The secret never crosses the network.

Next step: make sure the decrypted key is never written to #swap .

#networking #security

moozermoozer
2026-02-11

I use DNS01 got get for my internal servers. This works nicely and I don't have to worry about installing my own certificate in every device, workstation and server.
It has the drawback of everyone on the internet knows which servers I have on my domain.
Can I use ACME to get an intermediate certificate, that I can use for e.g. subdomain locally?

Dan Stafforddanstafford
2026-02-11

#2026

Microsoft warns Secure Boot certificates will expire in 2026 | Windows Central share.google/63ykWQCfLIUIduB0G

2026-02-10

#Linux #Win10 #SecureBoot #UEFI #Certificates

TL/DR
Does Linux have a fix/mitigation of this expiring cert issue?

Full post:

So an important/critical firmware level certificate from Microsoft is expiring in June - which will leave Win10 users even more vulnerable to malware.

And this article utterly fails to even *mention* linux.

Some googling indicates Linux in general depends on the Microsoft certificates for Secureboot/UEFI compatibility.

As a software dev of 30 years I'm technical enough to be comfortable in the innards and configs of stuff, but not terribly well versed in Linux under the hood.

pcmag.com/news/upgrade-now-mic

2026-02-08

Here's how you regenerate the ESX self-signed certificate and extra info about rhttpproxy the Envoy reverse proxy ESX uses.

thedxt.ca/2026/02/esx-regenera

#ESX #VMware #certificates #vExpert #Broadcom

The Eclectic Light Companyeclecticlight.co@web.brid.gy
2026-02-02
<p>Apple has just released security updates for macOS Catalina and Big Sur. Yes, you saw that right, macOS 10.15 Catalina and 11 Big Sur.</p>
<p>These are formally macOS Big Sur 11.7.11 and Catalina Security Update 2026-001. Although billed as security updates, these extend the security certificates required by iMessage, FaceTime and Mac activation so they will continue working after January 2027. If you&#8217;re still running macOS 10.15 or 11, they&#8217;re essential. However, there are no published security fixes for either.</p>
Mike Harrisonmeuon@fosstodon.org
2026-02-02

DANE is interesting
Checking out mails servers and saw a test for DANE. Time to learn something new? DANE = DNS-based Authentication of Named Entities. Poorly supported in end clients, but I'm liking the ideas presented for verifying what CA is supposed to be the issuing CA. A cross check. May also be useful for self-signed certs. Gonna have to play. en.wikipedia.org/wiki/DNS-base #certificates #dane #ssl #tls

2026-01-28

#Apple Patches Old Versions of #iOS to Keep #iMessage and #FaceTime Running

Apple is renewing #certificates for iOS versions dating back to 2013 to keep the lights on a little longer.
#security

wired.com/story/apple-patches-

Osna.FMosnafm
2026-01-26

According to a survey conducted by the opinion‑polling institute Forsa, German citizens overwhelmingly want to keep the telephone sickness‑certification system... news.osna.fm/?p=31957 |

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst