top | item 46286183

(no title)

nickf | 2 months ago

Sure, but in those examples - automation and short-lifetime certs are totally possible.

discuss

order

bigfatkitten|2 months ago

Except when it's not, because the system rarely (or never) touches the Internet.

nickf|2 months ago

It might never 'touch' the internet, but the certificates can be easily automated. They don't have to be reachable on the internet, they don't have to have access to modify DNS - but if you want any machine in the world to trust it by default, then yes - there'll need to be some effort to get a certificate there (which is an attestation that you control that FQDN at a point-in-time).