Hello everyone. Need some opinions here. Does it worth all the trouble to make things like jellyfin and immich run with HTTPS for services that are only accesible in the LAN? I ask it 'cause, as far as I know, there is no way to put a valid certificate like let’s encrypt for a service that is not accessible from the net and I don’t plan to buy a certificate for myself. But I have some trouble with the rest of my family having issue with their browsers complaining about the lack of https every time a browser is updated. So, what would be the best solution?

  • magic_smoke@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    4
    ·
    edit-2
    9 hours ago

    For inside the lan/lab, I have my pem chain looks like:

    cold storage root-ca -> offline vault qubes VM ca -> pfsense ca -> freeipa ca

    I use letsencrypt for externally facing services.

    Its a little bit more effort than getting things just workin’ but its worth the whole lotta security you get in return. Plus it feels nice looking at a shiny green lock.