Meine aktuelle private #QNAP #NAS Baustelle:

#SSLVPN (TCP 443) mit #OpenVPN (#QVPN App)
• Interne CA für .internal (#OpenSSL)
#PiHole (Docker) für .internal DNS A Records
• Reverse-Proxy #Caddy (Docker) für HTTPS
#Vaultwarden (Docker)
#FreshRSS (Docker)

Für den sehr sporadischen Dateizugriff verwende ich die Qfile-App.

Nur das SSL-VPN ist aus dem Internet erreichbar.

Weitere #Docker Ideen:
#Nextcloud (wenn Qfile nicht ausreicht)
#PaperlessNGX

#opensource #privatecloud #cloud

WHAT THE ACTUAL FUCKING FUCK‽‽‽‽

OpenSSL’s commandline-tool does not support AEAD ciphers, for, sorry to paraphrase,
no sane reason whatsoever!

It’s not that they don’t have them implemented, that it would be too much work, or anything like that (which would be respectable reasons), but because:

To support AEAD ciphers in the enc command, all of the output needs to be buffered before any is emitted. Letting something downstream use the data before it has been authenticated is a critical vulnerability.In other words it would be as much of a vulnerability as using an unauthenticated cipher would be, which is what they unironically propose as an alternative!

I really get why OpenBSD forked that shit-show of a library! We probably all should really have all moved to LibreSSL a long time ago. Like WTF?

#openssl #crypto

Why AEAD is not supported in command enc? · Issue #12220 · openssl/openssl

I run openssl -enc -aes-128-gcm and shows that AEAD ciphers not supported Why AEAD is not supported?Is there any consideration in designing the command line tools? Is there any other command to tes...

GitHub
wie validiert man ein signiertes pdf eines notars, für das eine #pkcs7 datei vorliegt mit #openssl? ich habe es auf die schnelle nicht hinbekommen bzw bekomme einen padding fehler.

On MacOS with Ruby v3.4 and openssl v3.6 if you're seeing an OpenSSL::SSL::SSLError exception with a message like "certificate verify failed (unable to get certificate CRL)", you can workaround/fix it by reinstalling Ruby against an earlier version of openssl, e.g. v3.5.

https://github.com/rails/rails/issues/55886#issuecomment-3411919148

#ruby #macos #openssl

SSL certificate verification fails on macOS (OpenSSL 3.6 + Ruby 3.4) due to CRL check · Issue #55886 · rails/rails

When running any HTTPS requests (e.g., through Net::HTTP, ActiveStorage::Service::S3Service, or AWS SDK) on macOS with Ruby 3.4.x and OpenSSL 3.6, SSL handshakes fail with the error: OpenSSL::SSL::...

GitHub

tfw u see "Installing dependency: openssl@3"

#openSSL #homebrew

The upgrade to #NixOS 25.11 was all that was needed to get support for post quantum safe X25519MLKEM768 key agreement!

https://isitquantumsafe.info/

(Should be supported out of the box by Nginx if you have #OpenSSL 3.5+ installed: https://openssl-library.org/post/2025-04-08-openssl-35-final-release/)

#PQ #PQS #PostQuantum #Nginx

Thanks to @vsz this is quickly becoming the most thorough and detailed resource on the #OpenSSL fork situation. Which fork does what and how?

https://github.com/curl/curl/wiki/OpenSSL-forks

OpenSSL forks

A command line tool and library for transferring data with URL syntax, supporting DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, POP3, POP3S, RTMP, RTMPS, RTSP...

GitHub
Selbst ist der #Nerd: Nachdem zuerst die web gui bei @mailbox_org meinen neuen p12 #sMime Schlüssel nicht importieren wollte. Einfach lokal via #OpenSSL in Private Key und Zertifikate zerlegt, wieder zu einem neuen p12 File vereint und hochgeladen. Siehe da: Funktioniert! 🤓 Der Fehler mag beim Aussteller oder beim Importieren liegen, wer weiß. Hauptsache gelöst.
There were many other great talks at the #OpenSSL conference, I encourage you to check them out at https://www.youtube.com/@OpenSSLConference. Some of my highlights in 🧵.
OpenSSL Conference

The official channel of the OpenSSL Conference Watch talks, panels, and interviews from the 2025 conference in Prague and stay tuned for updates on the next edition. Subscribe to follow the OpenSSL community, explore expert insights, and keep up with future events shaping the world of secure communications.

YouTube