RIOT Summit 2018 @ Amsterdam - TLS v1.3 and RIOT OS
RIOT Summit 2018 @ Amsterdam - TLS v1.3 and RIOT OS
Ah guck, und ne Erklärung worans lag kam auch gleich noch hinterher.
> In fact this problem is caused by Google because in the updated SSL provider TLSv1.3 is disabled by default. I think this is insane, but who am !?
Muss ihm da völlig zustimmen:
Google hat doch nicht mehr alle Latten am Zaun. Den #TLS Provider über die #GoogleDienste updaten für bessere Sicherheit, aber #TLSv13 by default ausschalten?!
api_url_buypass="https://api.buypass.com/acme/directory"
authority buypass {
api url $api_url_buypass
account key "/etc/acme/buypass-privkey.pem"
contact "<email>"
}
domain cybsec.network {
domain key "/etc/ssl/private/cybsec.network.key"
domain full chain certificate "/etc/ssl/cybsec.network.crt"
sign with buypass
challengedir "/var/www/acme/"
}
Still some things to iron out in reverse proxy setup to make tlsv1.3 in relayd work with Pomerium (I suppose).
#openbsd #openbsd68 #releaseday #buypass #acme #tlsv13 #relayd