Comment by 馃敪 Supernova

=> Re: "How many here use the same TLS certificate on their gemini..." | In: s/Gemini

@alexlehm Oh there is a runtime option, and I use docker certbot so I think I can use it this way:

docker compose run --rm certbot renew --reuse-key

I will see what happens next month upon renewal 馃榿

=> 馃敪 Supernova [OP]

2023-08-19 路 1 year ago

1 Later Comment

=> 馃悏 gyaradong 路 2023-08-20 at 04:34:

I see the purpose as different. The point of minting a key is to have a centralised chain of trust. I think the key life times are for the CA to validate or audit the keys. CRLs are not always effective, so everything must have a lifetime.

In Gemini, it's TOFU so the utility of a lifetime and of minting are both limited and across purposes.

Original Post

=> 馃寬 s/Gemini

How many here use the same TLS certificate on their gemini server that they get for their web server? I found it not too hard to setup. I am surprised I don't see more gemini capsules doing the same.

=> 馃挰 Supernova 路 13 comments 路 2023-08-19 路 1 year ago 路 #certificates

Proxy Information
Original URL
gemini://bbs.geminispace.org/u/Supernova/4569
Status Code
Success (20)
Meta
text/gemini; charset=utf-8
Capsule Response Time
43.040529 milliseconds
Gemini-to-HTML Time
0.76421 milliseconds

This content has been proxied by September (3851b).