Self-Signed locally trusted certificates with cert-manager
skarlso.github.io
skarlso.github.io
- register a subdomain on getlocalcert.net
- save credentials
- create LetsEncrypt certificate with cert-manager
Since LetsEncrypt is a trusted CA, there is no need for mkcert.
https://github.com/robalexdev/getlocalcert-client-tests/tree...
Which looks quite interesting to have HTTPS for my internal-only pages without need to deal with an external service, although you have to be very careful to setup your certs correctly with "Name Constraints" (https://www.rfc-editor.org/rfc/rfc5280#section-4.2.1.10) to avoid the risk of someone being able to MitM everything if they're able to get in and start issuing themselves certificates.
Thought I'd share some insights in how I set up test frameworks using cert-manager for generating self-signed certificates. And then making them locally trusted using mkcert for easy install.
I think it's neat, but it does have its caveats as everything I suppose. :)
Thanks!
I believe dealing with certificates that include the ability to end-to-end test them is never simple.
The first time you install it, it will prompt you to install the root cert.