OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
Posted Nov 18, 2020 22:49 UTC (Wed) by Cyberax (✭ supporter ✭, #52523)Parent article: OpenWrt and self-signed certificates
Posted Nov 18, 2020 23:02 UTC (Wed)
by gray_-_wolf (subscriber, #131074)
[Link]
> By default, LuCI does not listen on the internet-facing side of the router, but is available via both wired and wireless access on the local network, though the wireless network is not enabled by default for OpenWrt.
I've "solved" this by tunelling the luci over ssh and connecting to localhost. Seems to work well enough.
Posted Nov 18, 2020 23:41 UTC (Wed)
by thumperward (guest, #34368)
[Link] (7 responses)
openwrt is probably in a better situation than most of these use cases to be honest. At least there's plenty of work already in the wild permitting domestic routers to handle this.
Posted Nov 19, 2020 0:58 UTC (Thu)
by Cyberax (✭ supporter ✭, #52523)
[Link] (6 responses)
And anyway, self-signed HTTPS certs are unlikely to go away either.
Posted Nov 19, 2020 10:36 UTC (Thu)
by LtWorf (subscriber, #124958)
[Link] (5 responses)
Posted Nov 19, 2020 15:52 UTC (Thu)
by Lennie (subscriber, #49641)
[Link] (2 responses)
Posted Nov 21, 2020 17:33 UTC (Sat)
by LtWorf (subscriber, #124958)
[Link] (1 responses)
Posted Nov 23, 2020 22:52 UTC (Mon)
by Lennie (subscriber, #49641)
[Link]
I'm very much for something like archive.org making old software run again so people can use it as it used to be used.
I'm amazed at what has been possible: https://archive.org/details/win3_stock
https://bellard.org/jslinux/vm.html?url=win2k.cfg&mem...
But as we've seen for example Apple had a service which was used to check developer signing certificates. These kinds of things will make it harder and harder to keep old software running.
And full disk encryption will mean a device which isn't in use anymore because someone dies the data might be gone.
The reason the dark ages are called the dark ages is because we didn't have much books/records from then. We might be entering (if not already have) digital darkages.
Posted Nov 22, 2020 10:24 UTC (Sun)
by shx (guest, #105604)
[Link]
Posted Aug 4, 2021 3:24 UTC (Wed)
by Divadeer (guest, #153561)
[Link]
Posted Nov 19, 2020 12:22 UTC (Thu)
by epa (subscriber, #39769)
[Link] (12 responses)
Posted Nov 19, 2020 15:58 UTC (Thu)
by Lennie (subscriber, #49641)
[Link] (9 responses)
Have a local name: local.openwrt.org which has a known certificate and which can automatically be downloaded/updated.
It's not more secure, but at least more convenient.
The DNS-server on the OpenWRT device would overwrite* the name with it's own IP and thus a DHCP-client when resolving that name would point directly that OpenWRT device.
* For example Unbound has the local-data option:
Posted Nov 19, 2020 22:42 UTC (Thu)
by Fowl (subscriber, #65667)
[Link] (4 responses)
Posted Nov 20, 2020 4:53 UTC (Fri)
by tialaramex (subscriber, #21167)
[Link] (1 responses)
Posted Nov 20, 2020 8:34 UTC (Fri)
by Lennie (subscriber, #49641)
[Link]
And possibly the CA/B forum.
Posted Nov 23, 2020 14:22 UTC (Mon)
by epa (subscriber, #39769)
[Link] (1 responses)
Posted Nov 23, 2020 22:29 UTC (Mon)
by Lennie (subscriber, #49641)
[Link]
None of it is ideal obviously.
Posted Dec 3, 2020 11:49 UTC (Thu)
by akvadrako (guest, #131971)
[Link] (3 responses)
router.small-2.local.net A 192.168.2.1
Posted Dec 3, 2020 23:38 UTC (Thu)
by Fowl (subscriber, #65667)
[Link] (2 responses)
Posted Dec 4, 2020 18:19 UTC (Fri)
by akvadrako (guest, #131971)
[Link] (1 responses)
Posted Dec 5, 2020 4:07 UTC (Sat)
by Fowl (subscriber, #65667)
[Link]
Posted Nov 20, 2020 15:15 UTC (Fri)
by mebrown (subscriber, #7960)
[Link] (1 responses)
Posted Nov 22, 2020 4:52 UTC (Sun)
by diamondlovesyou (subscriber, #119529)
[Link]
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
There are no plans to disable HTTP completely. With the amount of other IoT stuff that uses HTTP internally.
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
router.big-2.local.net A 10.0.2.1
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates
OpenWrt and self-signed certificates