| ▲ | jillyboel a year ago | ||||||||||||||||
Getting my parents to add a CA to their android, iphone, windows laptop and macbook just so they can use my self hosted nextcloud sounds like an absolute nightmare. The nightmare only intensifies for small businesses that allow their users to bring their own devices (yes, yes, sacrilege but that is how small businesses operate). Not everything is a massive enterprise with an army of IT support personnel. | |||||||||||||||||
| ▲ | crote a year ago | parent | next [-] | ||||||||||||||||
Rolling out LetsEncrypt for a self-hosted Nextcloud instance is absolutely trivial. There are many reasons corporations might want to roll their own internal CA, but simple homelab scenarios like these couldn't be further from them. | |||||||||||||||||
| |||||||||||||||||
| ▲ | mysteria a year ago | parent | prev | next [-] | ||||||||||||||||
I actually do this for my homelab setup. Everyone basically gets the local CA installed for internal services as well as a client cert for RADIUS EAP-TLS and VPN authentication. Different devices are automatically routed to the correct VLAN and the initial onboarding doesn't take that long if you're used to the setup. Guests are issued a MSCHAP username and password for simplicity's sake. For internal web services I could use just Let's Encrypt but I need to deploy the client certs anyways for network access and I might as well just use my internal cert for everything. | |||||||||||||||||
| |||||||||||||||||
| ▲ | richardwhiuk a year ago | parent | prev [-] | ||||||||||||||||
Why are your parents on a corporations internal network? | |||||||||||||||||
| |||||||||||||||||