▲ | pavon 4 days ago | ||||||||||||||||||||||||||||||||||||||||
Yes, but it is a lot more work to run an internal CA and distribute that CA cert to all the corporate clients. In the past getting a public wildcard cert was the path of least resistance for internal sites - no network access needed, and you aren't leaking much info into the public log. That is changing now, and like you said it is probably a change for the better. | |||||||||||||||||||||||||||||||||||||||||
▲ | pkaye 4 days ago | parent | next [-] | ||||||||||||||||||||||||||||||||||||||||
What about something like step-ca? I got the free version working easily on my home network. | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
▲ | bravetraveler 4 days ago | parent | prev [-] | ||||||||||||||||||||||||||||||||||||||||
> A lot more work 'ipa-client-install' for those so motivated. Certificates are literally one among many things part of your domain services. If you're at the scale past what IPA/your domain can manage, well, c'est la vie. | |||||||||||||||||||||||||||||||||||||||||
|