Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Neslepaks
Sep 3, 2003

The thing I would recommend using a real subdomain that you own instead of e.g .local for is that you can get a wildcard cert from Letsencrypt and make ssl on local services a lot easier on yourself. I just recently switched to this from a cumbersome self-signed CA setup and it's :discourse:

Adbot
ADBOT LOVES YOU

Neslepaks
Sep 3, 2003

bobfather posted:

To explain that idea even more, you can set up Nginx Proxy Manager to grab your LetsEncrypt wildcard certs for your domain, create a proxy host that redirects subdomain.yourdomain.com to whatever internal service you are self-hosting, and then set your router to do a DNS host override to redirect traffic from subdomain.yourdomain.com to the host running Nginx Proxy Manager. Voilà - valid LetsEncrypt certs on any internal service you care to run.

I guess you could do that yeah. For my part I just have a wildcard cert for *.internal.mydomain.com that I use internally and then I just provision normal LE certs for anything external like https://www.mydomain.com.

Neslepaks
Sep 3, 2003

bobfather posted:

I think we’re talking about the same thing. I merely described one way to use a wildcard LE cert to secure services that are only available on the LAN.

Sorry yeah. I dist it out with ansible

Neslepaks
Sep 3, 2003

I've selfhosted email for nearly 25 years and honestly it's extremely hands off once it's set up. I know some people run into IP reputation issues and such but I haven't had any.

Neslepaks
Sep 3, 2003

FWIW I use Nextcloud to sync photos and though it has many warts of its own it's fine with what you describe.

Neslepaks
Sep 3, 2003

Yeah they're just files and you can browse them in the app or whatever. You can also two way sync to a pc using the deskop client if needed.

Neslepaks
Sep 3, 2003

Potato Salad posted:

rolling your own CA is so fun though :smithicide:

Rolling your own CA is actually a nightmare and I recommend against it. So many bothersome issues went away when I changed to a LE wildcard instead.

Neslepaks
Sep 3, 2003

Gandi is good.

Neslepaks
Sep 3, 2003

Potato Salad posted:

hey serious question, why use LE wildcard? It seems like one of the added values of using LE is that it's easy to get specific certs for each individual system / pool of systems and have them automatically maintained

For me it's partly that it's easier to dist a wildcard cert to various parts of my infrastructure, some of which may not have direct internet access, combined with a desire to not "leak" my hostnames to the world.

Neslepaks
Sep 3, 2003

Aware posted:

Don't host your own email.

Stop parroting this phrase. You can perfectly well host mail given the right circumstances.

But the OP doesn't want to maintain a postfix config so I'm not sure it's for him.

Neslepaks
Sep 3, 2003

Automate it with Ansible? That's what I'd reach for.

Neslepaks
Sep 3, 2003

I’m pretty happy with nextcloud tbqh. Phones upload pics automatically, files are shared, contacts are synced, calendars are calendaring. It all works and has for some years now.

Trying out some better frontends for photo browsing/searching but probably will keep the uploading through nc

Adbot
ADBOT LOVES YOU

Neslepaks
Sep 3, 2003

I’ve been trying out both photoprism and immich lately and while not fully decided I’m leaning photoprism mainly because immich is more resource hungry, has more moving parts and is slower to index. I also find it less intuitive in some ways, like when trying to rectify errors in face recognition. The wife and I share a common library so the user separation stuff is more in my way than helpful as well.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply