Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
view the rest of the comments
Certificate revocation is a joke and has been for over a decade
Huh, FF on Android doesn't care.
Most browsers don't, hence my calling revocation a joke.
So many in this thread are up in arms about something the majority of browsers don't care about and have actively ignored for as long as I can recall
Yeah, I was just surprised bc the page explicitly lauds FF for checking revocation.
It may only be the desktop version, most mobile browsers aren't as feature complete as their desktop counterparts.
But, given Google ripped revocation checking out of chromium, I wouldn't be surprised if they nerfed it in Android too...
Orion browser (maybe safari?) on iOS detected the revoked certificate, and asked me to confirm before accessing the website while warning about the dangers.
Does regular safari show the same prompt? Afaik, browsers on iOS are safari reskins, so I'm curious if they added his cert in directly again, or if the onion browser actually follows standards the os browser doesn't.
Yes, but safari doesn't even let me ignore the warning, it has a explanation in detail, and only allows closing the website.
You didn’t look hard enough. My router cert isn’t valid and I have to bypass the warning every time.
Maybe there’s a special case for local subnets?
Here’s what shows up for me (in portuguese):
Clicking on more details, only allows me to check the certificate:
Here’s the translated details:
Said certificate:
Edit: on the latest iOS version (27) btw.
Thanks for the proof! I stand corrected! I see basically the same but after the view link there is another think that bypasses it.
Must be difference between expired vs compromised cert.
If the certificate only lasts two months revocation isn’t necessary, just deny recertification.
And what if you need to get a new certificate?
You go to a different CA
Aren't we back at OP's question?