From 0f652b2d99855c8270aa65d8772f7e340f96f73d Mon Sep 17 00:00:00 2001 From: tslil clingman <> Date: Tue, 5 Oct 2021 23:06:17 -0400 Subject: Reveal tak to the world! --- log-211004-1.gmi | 10 ++++++++++ 1 file changed, 10 insertions(+) (limited to 'log-211004-1.gmi') diff --git a/log-211004-1.gmi b/log-211004-1.gmi index 1181b92..f9086dc 100644 --- a/log-211004-1.gmi +++ b/log-211004-1.gmi @@ -7,3 +7,13 @@ At some point between April and September 2021 my old SSL certs expired. I took In the end i went with gmnisrv, a small C implementation backed by OpenSSL. Among its draws is the fact that it automatically generates (and presumably maintains?) certificates. => https://sr.ht/~sircmpwn/gmnisrv/ gmnisrv + +## Later ... + +A kind sole not only read this, but was generous enough to reach out to help me learn about TOFU and Gemini practices. They directed me to the article + +=> gemini://warmedal.se/~bjorn/posts/your-gemini-browser-and-server-are-probably-doing-certificates-wrong.gmi + +and i learnt some things. Fortunately gmnisrv appears to have set something like an 80 year expiration on these new certs, so apparently its defaults are sane. + +To the helpful individual: if you'd like to be credited for point this out, i'd be happy to do so! Thanks for reading and educating! -- cgit v1.3.1