<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>.Ca on</title><link>https://dawning.ca/tags/.ca/</link><description>Recent content in .Ca on</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>Copyright © James Snell</copyright><lastBuildDate>Wed, 17 Jan 2018 15:17:57 +0000</lastBuildDate><atom:link href="https://dawning.ca/tags/.ca/index.xml" rel="self" type="application/rss+xml"/><item><title>Using pfsense to sign private wildcard SSL certificates</title><link>https://dawning.ca/posts/using-pfsense-to-sign-private-wildcard-ssl-certificates/</link><pubDate>Wed, 17 Jan 2018 15:17:57 +0000</pubDate><guid>https://dawning.ca/posts/using-pfsense-to-sign-private-wildcard-ssl-certificates/</guid><description>
&lt;p>&lt;figure>
&lt;picture>
&lt;img
loading="lazy"
decoding="async"
alt=""
class="image_figure image_internal image_unprocessed"
src="https://dawning.ca/uploads/2018/01/Screen-Shot-2018-01-17-at-3.09.38-PM.png"
/>
&lt;/picture>
&lt;/figure>
&lt;a href="https://www.pfsense.org/download/">pfsense&lt;/a> is a wonderful router appliance &lt;a href="https://en.wikipedia.org/wiki/FreeBSD">BSD&lt;/a> distro that I&amp;rsquo;ve enjoyed for some years now.&lt;/p>
&lt;p>I use the &lt;a href="https://doc.pfsense.org/index.php/Certificate_Management">pfsense certificate manager&lt;/a> to issue certs for my VPN client devices. For my Internet-facing life, I have legit SSL certs for everything, I&amp;rsquo;ve a neurosis about it. But it&amp;rsquo;s bothered me that for my LAN servers, I&amp;rsquo;ve continued to use Self-Signed certs for interfaces. Today I fix that.&lt;/p>
&lt;p>Here are my notes on how to create and sign a wild-card SSL cert using pfsense for internal use. Note that this approach means you will make your own certificate authority which then must have its root cert installed on any machine you want to use your own certs.&lt;/p></description></item><item><title>Dear Diary: GoDaddy Error Code 6007</title><link>https://dawning.ca/posts/dear-diary-godaddy-error-code-6007/</link><pubDate>Fri, 07 Apr 2017 09:36:01 +0000</pubDate><guid>https://dawning.ca/posts/dear-diary-godaddy-error-code-6007/</guid><description>
&lt;p>I&amp;rsquo;ve been working out a tolerable dynamic DNS solution for myself lately. After much effort, I&amp;rsquo;ve settled on running my own bind server (I last did this like 12 years ago, hah). I&amp;rsquo;ve written simple scripts that handle it for me and they work fine. However, I found for many of my domains hosted by GoDaddy, I couldn&amp;rsquo;t get it to use my new nameservers. Godaddy would let me switch my nameservers, but then they&amp;rsquo;d revert to their previous settings and I&amp;rsquo;d get an email containing the helpful message:&lt;/p></description></item></channel></rss>