You probably don’t need one, but it’s nice to have the option

    • ramble81@lemmy.zip
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago

      I mean you could already with a custom DNS server and internally controlled CA. Honestly IP certs are extremely bad unless you own the specific public IP block. If you’re borrowing an IP that’s registered to another company, even if you have a “static” IP, it risks being changed and you can’t port it somewhere else. Don’t even get me started on DHCP for internal systems.

  • pezhore@infosec.pub
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 day ago

    Don’t even need your own Certificate Authority - get a public domain and do a wildcard sub-domain from let’s encrypt.