💾 Archived View for bbs.geminispace.org › u › Supernova › 4569 captured on 2023-12-28 at 16:51:21. Gemini links have been rewritten to link to archived content

View Raw

More Information

⬅️ Previous capture (2023-11-14)

➡️ Next capture (2024-02-05)

🚧 View Differences

-=-=-=-=-=-=-

Comment by 🔭 Supernova

Re: "How many here use the same TLS certificate on their gemini..."

In: s/Gemini

@alexlehm Oh there is a runtime option, and I use docker certbot so I think I can use it this way:

docker compose run --rm certbot renew --reuse-key

I will see what happens next month upon renewal 😁

🔭 Supernova

Aug 19 · 4 months ago

1 Later Comment

🐉 gyaradong · Aug 20 at 04:34:

I see the purpose as different. The point of minting a key is to have a centralised chain of trust. I think the key life times are for the CA to validate or audit the keys. CRLs are not always effective, so everything must have a lifetime.

In Gemini, it's TOFU so the utility of a lifetime and of minting are both limited and across purposes.

Original Post

🌒 s/Gemini

How many here use the same TLS certificate on their gemini server that they get for their web server? I found it not too hard to setup. I am surprised I don't see more gemini capsules doing the same.

💬 Supernova · 13 comments · Aug 19 · 4 months ago · #certificates