2,693 karma · joined May 24, 2013
Where can I get a certificate with the CA flag set for mydomain.com? I did not know this was an option for mere mortals.
Anyway, your example is a good one as to why it's weird for Chrome to label these things as insecure.
If you were to control the user's machine, yes. But imagine you bought a shiny new internet connected coffee pot. Once you turn it on it does the following:
1. Coffeepot Determines its LAN IP address (e.g. 192.168.1.100)
2. Coffeepot connects to the coffeepot cloud service to register a dynamic DNS entry (e.g. user1.coffeepot.com) to point to its LAN IP address.
3. User is told they can access their coffeepot WebUI by going to user1.coffeepot.com, which resolves to 192.168.1.100
This is secure since the coffeepot can only be controlled if you are in the same network. Yet, since the coffeepot webui can only be reached if you are in its network, it is nearly impossible to get a valid SSL certificate on the coffeepot appliance.
> Presumably there is already some sort of communication going on if they're receiving Chrome updates.
There is a difference between outgoing network traffic and incoming network traffic. Only the latter requires open ports.
2. Let's Encrypt will send you an email if your certificate is going to expire in a month. This will normally never happen, since it is continuously renewed.
Just don't opt into the Paramiko control scheme, which isn't used by default except on RHEL6 anyway.
You can also set ssh_args in the config file to enable ControlMaster, etc. http://docs.ansible.com/ansible/latest/intro_configuration.h...
edit: Don't actually see a tutorial in the app. Maybe I'm confused with another app such as Swype, but the same technique seems to apply to all.
This works fine for me with GBoard. Are you drawing a little circle on the o to indicate you want the double letter?