34
submitted 1 day ago* (last edited 1 day ago) by K3can@lemmy.radio to c/selfhosted@lemmy.world

Wanted to share a quick blog post (see link) playing around with a couple methods of validating data origin and integrity without blindly relying on public CAs.

It's sort of a follow-up-to-a-follow-up on an earlier post about using Cloudlfare proxies to selfhost personal sites or services, but it really applies more to TLS and public CAs in general.

top 5 comments
sorted by: hot top new old
[-] min@lemmy.sdf.org 6 points 1 day ago

Could mTLS be used instead to force the browser to validate the correct cert?

[-] K3can@lemmy.radio 5 points 1 day ago* (last edited 1 day ago)

Not directly, but I believe mTLS would break if the traffic was intercepted/altered, so it sort of works to test the connection.

mTLS requires installing a certificate on the client device, though. If you're able to do that, then you're also able to pin the correct cert or install a custom CA. This would be the "enterprise" solution, as far as I know, but doesn't work well for public sites, since you can't always configure your end-users devices.

Edit: mTLS is still very useful, though. I use it to secure some of my services. It just doesn't solve this specific problem.

[-] K3can@lemmy.radio 4 points 1 day ago

I'll add: mTLS would only break because the client certs are typically signed by a private CA and the host is configured to only trust that specific CA (similar to the enterprise solution I referenced in the post).

If, for some reason, the host was configured to trust all of the typical public CAs, then mTLS would theoretically share the same problem.

If there's a concern that an adversary can rewrite hashes then why is there not a concern the public key could also be rewritten and the hashes signed with the fake key?

[-] non_burglar@lemmy.world 2 points 1 day ago
this post was submitted on 18 Aug 2026
34 points (100.0% liked)

Selfhosted

61512 readers
643 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS