160 karma · joined May 20, 2010
I prefer proxying of SSL (and automatic generations of LetsEncrypt certificates) using containers so that my web servers don't have to worry about that aspect of configuration.
To me, https://github.com/jbenet/hashpipe addresses a lot of these issues by pinning the content to a hash.
You can't force somebody to read and understand the install script, but at least those who do can know it's the one they verified in advance.
https://github.com/jwilder/nginx-proxy
https://github.com/JrCs/docker-letsencrypt-nginx-proxy-compa...
Since both are long running processes, it makes sense to keep them in separate containers.
This[1] would seem to indicate you can use a U2F device[2] as an alternative to providing a cell phone for verification.
[1] https://www.google.com/landing/2step/#tab=how-it-works
[2] http://googleonlinesecurity.blogspot.com/2014/10/strengtheni...
My mistake was that I didn't enable 2 factor authentication.
Kind of aggressive calling out Google's engineers when you couldn't bother protecting yourself with their free and easy to use security mechanisms.As to my original comment, you can probably get by without having full TCP load balancing.
I'd love to see the source of this (or something similar) so I could implement it privately. Any ideas?
Misspellings on your landing page don't inspire confidence.