Caddy vs. Nginx
-
@JaredBusch said in Caddy vs. Nginx:
Right, because I do not use a reverse proxy for a single system anywhere. If I need a RP, that is because I have multiple systems behind it.
I actually do that a bit, mostly just for standardization so I know to look for nginx or whatever proxy for certain functions and don't have to worry if it's a single use or multi-use system.
-
@JaredBusch said in Caddy vs. Nginx:
Yes, I want various security headers set, etc.
Caddy gets an A out of the box on ssllabs.com
-
@JaredBusch said in Caddy vs. Nginx:
You have to compile yourself if you want to use commercially.
This is not something I will ever want to use because of that.
Yeah that's kinda lame, but not a deal breaker. Nginx has to be compiled for more advanced use cases like WAF or certain HAProxy features.
It's a bit of a bitch, but once you script it. It isn't too bad to do upgrades going forward.
-
@VoIP_n00b said in Caddy vs. Nginx:
@JaredBusch said in Caddy vs. Nginx:
Yes, I want various security headers set, etc.
Caddy gets an A out of the box on ssllabs.com
But they wouldn't see it, right? Because you'd still have CloudFlare in front of it. So while it gets an A, what does that matter?
-
@VoIP_n00b said in Caddy vs. Nginx:
@JaredBusch said in Caddy vs. Nginx:
Yes, I want various security headers set, etc.
Caddy gets an A out of the box on ssllabs.com
They are owned by them, so that's pretty sus.
-
@IRJ said in Caddy vs. Nginx:
@JaredBusch said in Caddy vs. Nginx:
You have to compile yourself if you want to use commercially.
This is not something I will ever want to use because of that.
Yeah that's kinda lame, but not a deal breaker. Nginx has to be compiled for more advanced use cases like WAF or certain HAProxy features.
It's a bit of a bitch, but once you script it. It isn't too bad to do upgrades going forward.
A distro, or someone you know, can make open releases of it, though. It's Apache 2 license, so they can't make binaries personal only. They can make their own download personal only, I guess, but you could make an identical binary that is commercial. On the weird world of licensing. Really just makes them asshats if they really do that.
-
@scottalanmiller said in Caddy vs. Nginx:
@VoIP_n00b said in Caddy vs. Nginx:
@JaredBusch said in Caddy vs. Nginx:
Yes, I want various security headers set, etc.
Caddy gets an A out of the box on ssllabs.com
They are owned by them, so that's pretty sus.
About Qualys
Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of cloud-based security and compliance solutions with over 9,300 customers in more than 100 countries, including a majority of each of the Forbes Global 100 and Fortune 100. The Qualys Cloud Platform and integrated suite of solutions help organizations simplify security operations and lower the cost of compliance by delivering critical security intelligence on demand and automating the full spectrum of auditing, compliance and protection for IT systems and web applications. Founded in 1999, Qualys has established strategic partnerships with leading managed service providers and consulting organizations including Accenture, BT, Cognizant Technology Solutions, Deutsche Telekom, Fujitsu, HCL, HP Enterprise, IBM, Infosys, NTT, Optiv, SecureWorks, Tata Communications, Verizon and Wipro. The company is also a founding member of the Cloud Security Alliance (CSA). For more information, please visit www.qualys.com.
They are no NTG, I'll give you that.
-
@scottalanmiller said in Caddy vs. Nginx:
But they wouldn't see it, right? Because you'd still have CloudFlare in front of it. So while it gets an A, what does that matter?
I'm not using CF as a reserve proxy or origin certificates.
-
@VoIP_n00b said in Caddy vs. Nginx:
@scottalanmiller said in Caddy vs. Nginx:
But they wouldn't see it, right? Because you'd still have CloudFlare in front of it. So while it gets an A, what does that matter?
I'm not using CF as a reserve proxy or origin certificates.
Why? It adds a lot of performance and security. Regardless, whoever you use as your RP should be handling this.
-
@VoIP_n00b said in Caddy vs. Nginx:
@scottalanmiller said in Caddy vs. Nginx:
@VoIP_n00b said in Caddy vs. Nginx:
@JaredBusch said in Caddy vs. Nginx:
Yes, I want various security headers set, etc.
Caddy gets an A out of the box on ssllabs.com
They are owned by them, so that's pretty sus.
About Qualys
Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of cloud-based security and compliance solutions with over 9,300 customers in more than 100 countries, including a majority of each of the Forbes Global 100 and Fortune 100. The Qualys Cloud Platform and integrated suite of solutions help organizations simplify security operations and lower the cost of compliance by delivering critical security intelligence on demand and automating the full spectrum of auditing, compliance and protection for IT systems and web applications. Founded in 1999, Qualys has established strategic partnerships with leading managed service providers and consulting organizations including Accenture, BT, Cognizant Technology Solutions, Deutsche Telekom, Fujitsu, HCL, HP Enterprise, IBM, Infosys, NTT, Optiv, SecureWorks, Tata Communications, Verizon and Wipro. The company is also a founding member of the Cloud Security Alliance (CSA). For more information, please visit www.qualys.com.
What does anything here have to do with anything? You said that their product was certified, by them. Telling us who "them" is is neither here nor there. The point that their validation is worthless remains unaddressed.
-
@IRJ said in Caddy vs. Nginx:
@JaredBusch said in Caddy vs. Nginx:
You have to compile yourself if you want to use commercially.
This is not something I will ever want to use because of that.
Yeah that's kinda lame, but not a deal breaker. Nginx has to be compiled for more advanced use cases like WAF or certain HAProxy features.
It's a bit of a bitch, but once you script it. It isn't too bad to do upgrades going forward.
that doesn't seem to be a limitation anymore. I didn't see it on their documentation.
Also I didn't realize Arden Labs made this. That's pretty cool.