| handles | th_ / zmbcgn |
| pronouns | he/him |
PSA: Use the "accounturi" feature of Let's Encrypt CAA!
If you're hosting a safety/security-critical service, there's a way too unknown feature called "accounturi", that allows you to restrict TLS certificate issuance to a single Let's Encrypt account (and account private key).
You simply create a CAA record on your domain and put your LE account ID into it.
This means that attackers cannot issue TLS certificates and pull man-in-the-middle attacks on your host!

CAA is a type of DNS record that allows site owners to specify which Certificate Authorities (CAs) are allowed to issue certificates containing their domain names. It was first standardized in 2013, and the version we use today was standardized in 2019 by RFC 8659 and RFC 8657. By default, every public CA is allowed to issue certificates for any domain name in the public DNS, provided they validate control of that domain name. That means that if there’s a bug in any one of the many public CAs’ validation processes, every domain name is potentially affected. CAA provides a way for domain holders to reduce that risk.
Söder will kein AfD Verbot aber dass die AfD bundesweit als gesichert rechtsextrem geführt wird.
Ich sage es mal für die begriffsstutzigen Demokraten unter uns so: Solange man die AfD wählen kann obwohl sie gesichert rechtsextrem ist, wird sie gewählt, weil sie gesichert rechtsextrem ist.