ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login
    1. Topics
    2. Tags
    3. ssl
    Log in to post
    • All categories
    • wrx7mW

      Resolved-Exchange 2010 - UCC SSL Cert Renewal WTF

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion exchange 2010 ssl ssl certificates ucc req
      12
      1 Votes
      12 Posts
      2k Views
      T

      I had the same problem:

      Microsoft includes a command-line utility with Certificate Services called certutil. This utility performs various operations on certificate files, including converting them to and from base64 format.

      Note that this command is run on your certificate server, which, in your environment, may be different from your Exchange server. If so, you need to copy the binary .req file to the certificate server, or make it accessible via a shared network folder or removable storage device.

      Open a command prompt on the certificate server and navigate to the folder where your binary .req file is, then type the following command:

      certutil -encode yourbinaryinputfile yourasciioutputfile

      Example:
      certutil -encode der.exchange.example.com.req pem.exchange.example.com.req
      You can then open the output file in Notepad and confirm that it is in the correct format to upload to your certifying authority.

    • travisdh1T

      GoDaddy SSL and Exchange 2013, can't find CRL

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion godaddy ssl exchange 2013
      17
      1 Votes
      17 Posts
      3k Views
      dbeatoD

      @travisdh1 Sometimes you never know!

    • ObsolesceO

      How to install GitLab on Fedora 26 with AD CS SSL

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion gitlab fedora 26 fedora ssl https openssl pfx pem key
      2
      3 Votes
      2 Posts
      2k Views
      black3dynamiteB

      @tim_g
      Do you know what tools and scripts that is available when installing hyperv-tools?

    • Emad RE

      How to setup Nginx TLS certificate based Authentication (VPN alternative)

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion nginx tls ssl cert certificate authentication
      21
      3 Votes
      21 Posts
      7k Views
      JaredBuschJ

      @aaronstuder said in How to setup Nginx TLS certificate based Authentication (VPN alternative):

      @emad-r 3650 🙂

      One of the main reasons that normal certs cannot be bought with forever expiration is because then people would be less apt to update them as ciphers are broken.

      Look at how many people still use(d) SSLv1 SHA1, etc., long after they were proven broken.

    • scottalanmillerS

      What Exactly Is a VPN, Is HTTPS a VPN SAMIT Video

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion samit security networking vpn https ssl tunneling encryption youtube scott alan miller
      28
      4 Votes
      28 Posts
      5k Views
      scottalanmillerS

      @zubairkhanzhk you're welcome!

    • brianlittlejohnB

      Certbot Apache plugin broken in Fedora 26

      Watching Ignoring Scheduled Pinned Locked Moved Solved IT Discussion lets encrypt certbot apache fredora linux fedora 26 ssl ssl certificates tls
      20
      2 Votes
      20 Posts
      5k Views
      JaredBuschJ

      @zachary715 said in Certbot Apache plugin broken in Fedora 26:

      @scottalanmiller said in Certbot Apache plugin broken in Fedora 26:

      I ran into this issue, forgot about this thread, went through LetsEncrypt's threads and their solution for this problem led me... here! Very nice.

      Just did the exact same thing. Let'sEncrypt forum had the link which led me here right about the time @JaredBusch was responding in my other thread.

      It has been posted on here more than one time. I should probably find one of those posts and make @scottalanmiller tag it appropriately.

      Edit: Or too slow..

    • EddieJenningsE

      OpenSSL CSR with Subject Alternative Name

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion openssl how-to san subject alternative name csr pki certificates ssl tls
      5
      1 Votes
      5 Posts
      3k Views
      EddieJenningsE

      @JaredBusch said in OpenSSL CSR with Subject Alternative Name:

      @EddieJennings said in OpenSSL CSR with Subject Alternative Name:

      @JaredBusch Correct. The "ye olde way" is how I've typically made a CSR and private key. The link I included talks about making a configuration file, which allows you to include SAN in your CSR.

      Ah, did not read the link. Yes, using a config file is the only method to get any SAN on a cert with OpenSSL.

      And after re-reading my post, I realized how terrible it was :(. I was hoping to find a one liner kind of thing, but alas. That particular article made it clear how to do it.

    • JaredBuschJ

      Updating FOP2 to work with HTTPS correctly

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion fop2 freepbx freepbx setup freepbx 13 ssl
      2
      3 Votes
      2 Posts
      2k Views
      JaredBuschJ

      For anyone not familiar, here is a screenshot of my free version.
      0_1492617573275_upload-25f91f66-c1ba-4ae2-817f-456db86124b3

      here is a paid version at a client with ~40 extensions.
      (intentionally not all are shown such as the Snom PA-1 paging adapter, because I know someone will count....)
      0_1492617629380_upload-221e49df-6efb-4acd-b371-c5146c52a84e

    • ObsolesceO

      IIS and LetsEncrypt

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion iis lets encrypt ssl certificates ssl
      3
      1 Votes
      3 Posts
      2k Views
      ObsolesceO

      @NashBrydges Oh this is awesome! Gonna be giving that a go on Monday or Tuesday.

    • AmbarishrhA

      DNS record will help prevent unauthorized SSL certificates

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion dns ssl
      4
      5 Votes
      4 Posts
      1k Views
      dafyreD

      @StrongBad said in DNS record will help prevent unauthorized SSL certificates:

      Not a bad idea, I guess. There is some security concern there. I would wonder how often this is really an issue. Is this common? Or just proactive?

      I'm thinking a bit of both.

    • scottalanmillerS

      Deploying an NGinx Reverse Proxy with SSL on a LAMP Server with SaltStack

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion lamp proxy reverse proxy nginx salt saltstack devops web server lets encrypt ssl tls https https2
      42
      2 Votes
      42 Posts
      8k Views
      stacksofplatesS

      This way you can share the config(s) under conf.d between multiple machines using the same roles (or whatever Salt calls them) and have different main NGINX server settings.

    • travisdh1T

      Updates to SSL Labs testing methods in 2017.

      Watching Ignoring Scheduled Pinned Locked Moved News ssl security server update 2017
      1
      1 Votes
      1 Posts
      782 Views
      No one has replied
    • JaredBuschJ

      Let's Encrypt stats

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion lets encrypt ssl ninja tld encryption
      7
      3 Votes
      7 Posts
      2k Views
      dafyreD

      @scottalanmiller said in Let's Encrypt stats:

      @Jason said in Let's Encrypt stats:

      I'm guessing a lot of kids/teens and college age are using let's encrpyt hence the .ninja

      I'm confused, aren't all those domains only used by ninjas?

      Go Ninja, Go Ninja, Go!

    • scottalanmillerS

      Forced HTTPS Is Now On

      Watching Ignoring Scheduled Pinned Locked Moved Announcements mangolassi ssl
      50
      7 Votes
      50 Posts
      13k Views
      minionM

      https://www.data-vocabulary.org/ - Works.

      https://schema.org/ - Works

    • AdamFA

      FreePBX, SelfSigned Certs, & Let's Encrypt

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion ssl certificates ssl lets encrypt freepbx
      18
      1 Votes
      18 Posts
      8k Views
      scottalanmillerS

      Yeah, that's a really awesome feature.

    • AmbarishrhA

      Let's Encrypt is now used around 4.86%

      Watching Ignoring Scheduled Pinned Locked Moved News ssl ssl certificates lets encrypt
      14
      1 Votes
      14 Posts
      4k Views
      JaredBuschJ

      @scottalanmiller said in Let's Encrypt is now used around 4.86%:

      Yeah, probably a lot less than a year before LE rules the roost. Maybe four more months? In a year it will have significant dominance, I am guessing.

      More likely about this time next year because they did not come out of beta until March

    • thwrT

      pfSense slow site-to-site VPN

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion freebsd pf pfsense openvpn vpn ssl ssl vpn networking
      19
      2 Votes
      19 Posts
      10k Views
      thwrT

      @marcinozga Thanks, but already tried net.inet.ip.fastforwarding in all combinations with TCP and UDP.

    • AmbarishrhA

      Let's Encrypt on ASO shared server

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion aso lets encrypt ssl
      7
      2 Votes
      7 Posts
      2k Views
      AmbarishrhA

      @scottalanmiller said:

      @Ambarishrh said:

      Wanted to setup Let's Encrypt for my blog which is now hosted on ASO but as per their tech agent, this is not possible! 😞

      Is that because SSL is not offered at all?

      As per them, its only on dedicated servers and not shared. But using https://gethttpsforfree.com/ i was able to generate certs and install 🙂

    • A

      HTTPS Everywhere: Encryption for All WordPress.com Sites

      Watching Ignoring Scheduled Pinned Locked Moved News wordpress security encryption ssl lets encrypt
      29
      4 Votes
      29 Posts
      5k Views
      scottalanmillerS

      @tonyshowoff said:

      @scottalanmiller said:

      @tonyshowoff said:

      @Dashrender said:

      @scottalanmiller said:

      @Dashrender said:

      Frankly, I'm frustrated that ICANN has allows so many registrars and SSL cert providers. There are over 1400 CAs trusted by Windows in 2010.

      Any one of those CAs can be compromised and their root cert used to sign fake certs for any site on the internet, instantly having Windows trust those certs.

      The whole security model on the internet is just broken. We don't have secure DNS or reliable Certificate Pinning.

      It would be a monopoly if they didn't make it basically open. Or monopoly-ish. Not an open market.

      Frankly, in this case, a monopoly, like you want for healthcare, seems like the better play. The fees should either be free or extremely low, only enough to handle the costs of administration and hardware required.

      Universal coverage does not imply monopolistic treatment. Further, most countries with universal health coverage also have private systems too.

      Like Panama... good healthcare for free or suckers can pay for private American healthcare from Johns Hopkins.

      Or Bosnia, the only place I know of where the "free" is way worse than private to an insane degree, and that's because of a war so at least that's an excuse.

      Johns Hopkins is the hospital that thought that nut job who thinks the pyramids were grain stores and all kinds of whacky things led their surgical department. You'd have to be insane to get treated at a hospital letting crazies like that even work there let alone run departments.

      (Working there as a janitor would be okay, just not in healthcare portions of the business.)

      That's the kind of hospital that removes your spleen because "if God wanted you to have it, he'd not have made it make you sick." Those people scare me.

    • 1
    • 2
    • 3
    • 2 / 3