Toot

Written by 2xsaiko on 2024-12-20 at 20:55

This seems super overcomplicated. What I would do is put all the subdomains on the public DNS, let HTTP(S) through the firewall for the respective hosts, deny everything from outside of your local network on the http server that isn’t under the DNS challenge path and then run the DNS challenge as you would for a public site.

Then you can get certs, everyone outside trying to access will get 403, and inside the network you can access as normal.

Of course you’ll have to trust your http server’s ACL for that, but I’m just going to assume servers like nginx (which I use) have a reliable implementation.

=> More informations about this toot | View the thread | More toots from 2xsaiko@discuss.tchncs.de

Mentions

=> View ComradeMiao@lemmy.dbzer0.com profile

Tags

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113687144100515641
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
220.481833 milliseconds
Gemini-to-HTML Time
0.600917 milliseconds

This content has been proxied by September (3851b).