mamot.fr is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mamot.fr est un serveur Mastodon francophone, géré par La Quadrature du Net.

Server stats:

3.5K
active users

#letsencrypt

17 posts11 participants2 posts today
Replied in thread

@tom_webb We've already blocked whole #amazon, #microsoft and #meta subnets. Amazon particularly is tricky because we still want #letsencrypt to work. Now we're doing manual checks in access logs every time our servers are down and adding malicious actors to iptable blocks. We'll need a weekend hackaton at our selfhosting collective to put preventions in place and maybe come up with some new ideas as well. ☣️ poisoning those bots seems like an appropriate response.

Random #SelfHosting tip for any who might be interested:

If you use #GetSSL to get your #LetsEncrypt certs, you'll get four files:

* The key (example.com.key)
* The domain cert (example.com.crt)
* The CA cert (chain.crt)
* The "full chain" cert (fullchain.crt)

Make sure to use the full chain cert, *not* the domain cert, when setting up your server. Otherwise some services will give you "unknown authority" errors.

How to Install Centmin Mod on #AlmaLinux #VPS Here's a detailed step-by-step guide on how to install Centmin Mod on AlmaLinux VPS server.
What is Centmin Mod?
Centmin Mod is a shell-based, menu-driven installer that automates the deployment of a LEMP (Linux, Nginx, MariaDB/MySQL, PHP-FPM) stack on CentOS, AlmaLinux, and Rocky Linux servers. Designed for efficiency and performance, it streamlines the installation and ...
Continued 👉 blog.radwebhosting.com/how-to- #php #centminmod #letsencrypt #csf

How to Install Centmin Mod on AlmaLinux VPS
RadWeb, LLC · How To Install Centmin Mod On AlmaLinux VPS - VPS Hosting Blog | Dedicated Servers | Reseller HostingHere's a detailed step-by-step guide on how to install Centmin Mod on AlmaLinux VPS server.

Built a bit of intranet tooling in recent weeks. I had #certbot renew our wildcard #LetsEncrypt certificate, but installing it on multiple internal services was a manual process. So I made an #Ansible playbook, but still had to run it manually. When? A cron job was checking the TLS certificate of our intranet every week. If its validity was less than 3 weeks I got an alert via healthchecks.io.
Only today I realised that certbot can run the playbook directly as a deploy hook...

Un Ordine Esecutivo di #Trump blocca i pagamenti all'#OpenTechnologyFund. Da essi dipendono servizi #FOSS critici come #FDroid, #TOR e #LetsEncrypt. Abbiamo bisogno di un impegno serio da parte dell'Unione Europea nello sviluppo di alternative FOSS prima possibile, è seriamente una questione di sicurezza molto più che di principio.
dday.it/redazione/52530/trump-

DDay.it · Trump farà saltare il negozio open-source Android F-Droid e la rete TorBy Sergio Donato

Let's Encrypt

In infosec.exchange/@aral@mastodo @aral wants us to pay taxes to keep Let's Encrypt "alive". Here's another reason NOT to do that.

Apparently the *.eu.org domain needed laundrying because it's reputation became too bad. So scammers create zillions of insane domain names and obtain *FREE* (for them) certificates for those sites. Usually such sites are not malicious; they're intended to have virusscanners remove detection, eventually for the sub-TLD ".eu.org".

To see this, you may consider opening
crt.sh?q=eu.org
but that will fail because there are WAY too many results.

To restrict the amount of records, try a subdomain name and further restrict output by deduplicating and restricting to not expired, as follows:

crt.sh/?Identity=madaline.eu.o

The screenshot below gives an idea (they're all Let's Encrypt certs by the way, and I marked one with an insane domain name).

I wrote about this phenomenon before, e.g. in security.nl/posting/781057/Let (at the time I did not understand why yet).

VirusTotal knows of 72.5K direct subdomains of *.eu.org:

"Subdomains (72.5 K)"

(open the RELATIONS tab in virustotal.com/gui/domain/eu.o).

@TheDutchChief @EUCommission @letsencrypt @nlnet

»Unsicherheit – US-Kürzungsrausch gefährdet für das Internet wichtige Open-Source-Projekte:
Die neue US-Regierung entzieht dem Open Technology Fund (OTF) die Mittel. Von diesem sind unter anderem @letsencrypt, @torproject und @fdroidorg finanziell abhängig. Der OTF hat Klage eingereicht«

Sehr heikel und es petrifft, wenn auch "nur" indirekt, alle Menschen auf der Erde. Der Egoismus eines Irren kann uns alle betreffen!

👉 derstandard.at/story/300000026

DER STANDARD · US-Kürzungsrausch gefährdet für das Internet wichtige Open-Source-ProjekteDie neue US-Regierung entzieht dem Open Technology Fund die Mittel. Von diesem sind unter anderem Let’s Encrypt, Tor und F-Droid finanziell abhängig. Der OTF hat Klage eingereicht
#trump#uspol#tor

Ok.. it actually is that simple: medium.com/@mariovanrooij/addi

I don't know how many times I screwed that up in so many mysterious ways - mainly 'cause I was trying *somehow* to not have to run my script as root. It feels strange to run anything as root - you just don't do that, right?

But fine... #LetsEncrypt is pretty easy and awesome. It solves my #Firefox's fear of my little VM. I like to see machines getting along.

Medium · Adding HTTPS to FastAPI - Mario van Rooij - MediumBy Mario van Rooij

#HELP

I just received a concerning email from the OTF (@opentechfund.bsky.social) stating that a major source of their funding is in jeopardy.

If you care about open-source, anti-censorship, or the open internet, please consider supporting one of the projects they fund.

#FOSS #OpenSource #TechNews
#USPol #Politics #News #PoliticalNews
#NetNeutrality #EFF
#Wikimedia #Signal #SignalApp
#TOR #TAILs #OpenVPN #VPN #LetsEncrypt #HTTPS #SSL
#Censorship #AntiCensorship

opentech.fund/projects-we-supp

"Franse overheid voert phishingtest uit op 2,5 miljoen leerlingen"
security.nl/posting/881630/Fra

KRANKZINNIG!

Het is meestal onmogelijk om nepberichten (e-mail, SMS, ChatApp, social media en papieren post - zie plaatje) betrouwbaar van echte te kunnen onderscheiden.

Tegen phishing en vooral nepwebsites is echter prima iets te doen, zoals ik vandaag nogmaals beschreef in security.nl/posting/881655.

(Big Tech en luie websitebeheerders willen dat niet, dus is en blijft het een enorm gevecht).

Replied in thread

@Datenproletarier das stimmt so nicht. Es gibt auch noch Unternehmen wie ZeroSSL oder Buypass die auch ACME kompatibel sind. Aber ja auch diese gehören evtl. zu US Unternehmen auch wenn ZeroSSL in Wien ansässig ist aber zu Assa Abloy bzw. deren US Tochter HID Global gehört. Buypass kommt aus Norwegen, gehört aber irgendwie einem kanadischen Unternehmen.

Aber ja eine echt unabhängige ggf. vom Sovereign Tech Fund finanzierte europäische Alternative wäre sinnvoll. Eigentlist ist alles vorhanden, man müsste es nur zusammensetzen und finanzieren.
@sovtechfund

#unplugtrump #datenschutz #letsencrypt