Joerg Jaspert :debian: · @Ganneff
266 followers · 869 posts · Server fulda.social

Using , is there really no "self-service" web interface? Where a user can login and do nothing beside changing their password, setting up OTP, download a config and (if needed) renew their users (for that VPN)?

Right now it seems, if using OTP, an admin has to create the initial secret. Tell that to the user somehow. Also tell them initial password. Then user can login - and change password / request new OTP seed. But *nothing* else.

There appears to be no way to get the user a VPN config safely, have them update their cert once a year (default lifetime 397 days). Except for an admin doing the work of exporting the VPN config/cert and storing those exports in some other system, to which the user then needs access to download their config (or updated cert).

Really?

I hope I only miss stuff, this would be a *huge* point against OPNsense, unfortunately. I can't have an admin go and recreate things all the time.

Soo, what did I miss?

#opnsense #VPN #x509 #cert

Last updated 1 year ago

Kevin Karhan :verified: · @kkarhan
1010 followers · 60906 posts · Server mstdn.social

@dangoodin I doubt this to be the case - survive in regulatory bs nieches, and will be unremoveable since not every platform & application will allow auth via certs, # or and you can't force everything to be or using a centralized server...

#online #pubkeys #ssh #gnupg #x509 #passwords #fax

Last updated 2 years ago

icinga (inofficial) · @icinga
20 followers · 149 posts · Server social.tchncs.de
robalex · @robalex
4 followers · 48 posts · Server indieweb.social

In Name "Constrain't" I show that handling of the name constraint extension in isn't consistent with developer expectations or other web browsers. But the new beta release is aligning Chrome!

alexsci.com/blog/name-non-cons

#chrome #x509 #tls

Last updated 2 years ago

:mastodon: aytin :fedora: · @aytin
25 followers · 203 posts · Server mastodon.uno

Ho cercato di sintetizzare e semplificare al massimo l'insieme di operazioni che faccio quando ho bisogno di creare una catena di certificati per i miei laboratori o per uso personale, allo scopo di far diventare l'operazione meno complicata di quanto sarebbe realmente.

noblogo.org/aytin/come-creare-

#digitalcertificate #x509 #csr #openssl #ca #cryptography #asymmetricencryption #symmetricencryption #digitalsignature

Last updated 2 years ago

Joel Goguen · @jgoguen
244 followers · 1 posts · Server hachyderm.io

Hello (again) World!

I suppose it's probably about time for another since I’ve moved servers. Hi! I'm me. You know I'm me because I said so, and this is the Internet so why would I lie?

I'm a , currently focusing on securing client devices (your employee laptops/desktops/phones) and . I like to think I'm reasonably competent with certificates and .

#introduction #security #generalist #zerotrust #x509 #2fa

Last updated 2 years ago

Stewart Russell · @scruss
189 followers · 819 posts · Server xoxo.zone

I love that the ham radio community decided that the best way to validate radio contact logs was to massively over-engineer an X.509 public key cryptography solution

Logbook of the World — lotw.arrl.org/lotw-help/

#x509 #encryption #hamradio

Last updated 2 years ago

:mastodon: aytin :fedora: · @aytin
18 followers · 181 posts · Server mastodon.uno
:mastodon: aytin :fedora: · @aytin
18 followers · 181 posts · Server mastodon.uno
:mastodon: aytin :fedora: · @aytin
18 followers · 181 posts · Server mastodon.uno
bertrand 🏃 👨‍💻 · @bertrand
167 followers · 911 posts · Server piaille.fr

@iamkale certificates are , not or . on the other hand can be either ssl or TLS and both make use of those x509 certificates.
And yep, I too say SSL connection when I should say TLS connection ^^

Oh and x509 certificates can be generated using 🙃

#x509 #tls #ssl #https #openssl

Last updated 2 years ago

bertrand 🏃 👨‍💻 · @bertrand
156 followers · 864 posts · Server piaille.fr

@kidehen @meneer @aniltj @w3c

OK so a self-issued cert is used to authenticate the user.

However it's referenced in the enterprise LDAP after some enrolment took place I guess? Like a FIDO2 pub key is stored server-side after enrolment. And the user attributes are not coming from the self-issued cert but from that enrolment phase.

I can see that happening eventually (though UX vs , there's not really much of a match here...)

#x509 #fido2

Last updated 2 years ago

bertrand 🏃 👨‍💻 · @bertrand
156 followers · 864 posts · Server piaille.fr

@kidehen @meneer @aniltj @w3c
Very few enterprises if any want to deal with any self-issued credentials when we're dealing with *B2E* access control. They already have a hard time maintaining identity quality and proofing without having to trust user issued data, especially for non public access (it's not because I self-issue the CEO title that I can have access to those documents)

#x509 #tls

Last updated 2 years ago

bertrand 🏃 👨‍💻 · @bertrand
156 followers · 864 posts · Server piaille.fr

@kidehen @meneer @aniltj @w3c
How will a selfsigned CA scale better than PGP?
If as a person, app or organisation I want strong assurance about a returning identity (ie proof of possession) I already can do that with FIDO2 (or X509 but the former is the current cool kid on the block)
Neither nor selfsigned solves identity proofing. They're as good as FB so that says a lot 😊

#fido2 #x509 #identity #authenticity #zerotrust #pgp #ssi

Last updated 2 years ago

bertrand 🏃 👨‍💻 · @bertrand
156 followers · 864 posts · Server piaille.fr

@kidehen @meneer @aniltj @w3c
Mmh 🤔, who apart from my employer can provide a VC stating my employment status? Who can certify my diploma? Who can provide a VC stating my health insurance status? Who can provide a VC certifying my legal identity? I definitely need 3rd parties to issue those VCs right.

#identity #authenticity #x509 #tls #ssi #privacy #internet #web #verifiablecredentials

Last updated 2 years ago

Kingsley Uyi Idehen · @kidehen
469 followers · 1118 posts · Server mastodon.social

@youid @Mastodon Regarding verification of claims in my profile doc, here's how that objective is achieved via using a custom handshake.

tinyurl.com/2p923xap

Custom Handshake?
Credentials in my public profile doc are looked-up and matched to equivalents in my locally held cert, following completion of the conventional handshake.

#https #x509 #linkinbio #identity #authenticity #ssi #youid #netid #webid #privacy #tls

Last updated 2 years ago

Jürgen · @elbosso
97 followers · 3431 posts · Server mastodon.social

aaaahhh - ein guter tag: rfc-editor.org/info/rfc9310 ist gerade verabschiedet und die github.com/elbosso/expect-dial kann bereits bei der erzeugung entsprechender CSRs unterstützen und konforme erstellen! näheres dazu bald auf elbosso.github.io/

#rfc9130 #x509 #certificates

Last updated 2 years ago

David J. Bianco (He/Him) · @DavidJBianco
1009 followers · 153 posts · Server infosec.exchange

In case you're having "that kind" of day, I just spent 10 minutes trying to figure out what the "/Q=" part of an distinguished name was supposed to be, before realizing my monitor was dusty.

#x509

Last updated 2 years ago

YouID™ · @youid
4 followers · 8 posts · Server mastodon.social

Here's a that demonstrates the creation of verifiable credentials ( cert and associated Private Key) using my edition on an .

youtube.com/watch?v=JlHLkxW_Xq

#screencast #x509 #iOS #iphone #ssi

Last updated 2 years ago

Kingsley Uyi Idehen · @kidehen
401 followers · 821 posts · Server mastodon.social

More and grief. Using the latest and greatest release of on , I can no longer find the "Trust Center" module for setting the preferred cert to be used for digitally signing my emails. Basically, it just selects what it sees as the default from my collection -- magically :(

All of this when via email remains the prevalent tool for tinkering with , , and by bad actors!

#smime #email #outlook #macos #x509 #phishing #privacy #security #democracy

Last updated 2 years ago