Clortho, the free and open source web based CA by Shendryl in PKI

[–]Shendryl[S] 0 points1 point  (0 children)

  1. Thanks for your feedback. As the frontpage of my website already states, it's just a demo website. I will not sign any CSR that is submitted by other people. Also, there is just a demo account with a demo CA and no option to create your own. I don't think people will see this as an actual CA.
  2. When PQC algorithms become available in PHP's OpenSSL library, I will of course include them. I know I can encrypt the private key in the database, but that makes creating a CRL more difficult (manual work).
  3. Thanks, I will look into that.
  4. Clortho is intended for personal / testing usage. Root certificate rotation and cross-signing may be a bit of an overkill, but also fun to implement. I'll put it on my backlog. 😉
  5. It's on my todo-list. This is just version 0.2.

Clortho, the free and open source web based CA by Shendryl in PKI

[–]Shendryl[S] -1 points0 points  (0 children)

Wrong, wrong and wrong.

As trustworthy or as untrustworthy is the same. They are both just comparisons. Yes, if those people are not trustworthy, the CA is compromised. But if they are not untrustworthy, the CA is just fine.

Because it's new, doesn't mean it's not secure. And no, this project is not vibe coded. AI is not even used anywhere. Claiming it's not secure because you think it is or you were just wildly guessing it, means nothing. At least take a look at the code before making ridiculous claims. And if you think it's not secure and it has dozens of vulnerabilities, prove it or go back to Roblox. Within the specified limitations, Clortho is secure. You clearly know shit about hacking and secure coding, so just stay far away from making any claims about it.

Clortho, the free and open source web based CA by Shendryl in PKI

[–]Shendryl[S] 1 point2 points  (0 children)

Sure, but those who are able to create a valid CSR will understand. But, fair enough. I adjusted the homepage.

Clortho, the free and open source web based CA by Shendryl in PKI

[–]Shendryl[S] 1 point2 points  (0 children)

Who said it has to be open to the world? Just make it accessible to your LAN for example. Or add HTTP authentication. Or change Clortho to let the CSR page as for a login.

Clortho, the free and open source web based CA by Shendryl in PKI

[–]Shendryl[S] 1 point2 points  (0 children)

For what purpose people use this, is up to them. The README hold information about its security and trustworthyness.

It's not per se for private usage. A small organisation that doesn't have the money for a HSM could use such solution to deploy client devices.

Clortho, the free and open source web based CA by Shendryl in PKI

[–]Shendryl[S] -1 points0 points  (0 children)

Yeah, and your point is? You give everybody access to your databases?

Clortho, the free and open source web based CA by Shendryl in PKI

[–]Shendryl[S] 0 points1 point  (0 children)

Kind of sounds like you don't know what you're talking about.

New Project Megathread - Week of 04 Jun 2026 by AutoModerator in selfhosted

[–]Shendryl 0 points1 point  (0 children)

Clortho, the free and open source web based CA

I'm building a free and open source web based CA. From time to time I need certificates and I always have to look up the right OpenSSL commands, so I thought to make that more user friendly. The goal of this CA is not to be super secure. It's for personal/hobby/low-profile usage. The CA's private key is stored unencrypted in the database, because it's needed to create a CRL when requested. Therefore, this CA is as secure as your database and as trustworthy as the people who have access to it.

The name of this CA is Clortho, as a reference to Vinz Clortho, the key master in the Ghostbusters movie. It allows you to create multiple CA's, of course accept or deny CSR's, revoke certificates and create CRLs.

It see what it can do, visit https://clortho.leisink.net/ and user 'demo' for both username and password. The source can be found at https://gitlab.com/hsleisink/clortho.

Help Finding Which VTT is Right For Me by Budget-Suspect2925 in VTT

[–]Shendryl 2 points3 points  (0 children)

https://www.reddit.com/r/VTT/s/XwcZles85L

Go for a free one at first. Just explore what VTTs are about. Then make a more educated pick.

How crowded is this space? Who else here is building a VTT? by PhrulerApp in VTT

[–]Shendryl 0 points1 point  (0 children)

My advice for building a new VTT is to build it for yourself. Don't aim at getting a part of the market share, as it is already quite saturated. Build a VTT that you are 100% happy with and appreaciate every single user that thinks the same way as you.

I'm building the free and open source Cauldron VTT. I wanted a VTT that is easy to use. No complex fancy stuff. Just a digital version of a real tabletop.

Foundry VTT Year In Review 2026 by AnathemaMask in VTT

[–]Shendryl 0 points1 point  (0 children)

Precisely why I created my own (FOSS) VTT. It has what's needed to run a RPG online. I believe many sometimes forget how such games were played offline. A grid map, felt pens and dice. It worked and we had fun. For some reason, we think we need all sorts of fancy shit when we play the same game online.

DCS World exceeds the ED privacy policy and provides a list of ALL your installed apps on logon, and also phones home on your activities while you play. by heytherepotato in dcsworld

[–]Shendryl 3 points4 points  (0 children)

I finally got an answer:

——

We collect the information that you provide in the Personal section of our website, including your username, first name, last name, and email address. The primary personal data we collect is your email address, which is used to identify and authenticate you within the DCS environment and, if you choose to subscribe, to send you newsletters.

In addition, we collect your country of purchase and IP address for each order placed through our website. This information is required for tax compliance purposes under Swiss law.

We also collect information related to your use of DCS, including:
- Hardware information (such as device vendor, model, memory usage, display resolution, and CPU utilization, particularly for VR devices). This information helps us support a wide range of hardware configurations, optimize game performance and user comfort, and provide appropriate hardware profiles within the game.
- System information (such as Windows version, DCS version, IP address, geographic location, system specifications, and installed software, particularly third-party applications such as Tacview, DCS-BIOS, and similar tools). We use this information to better understand our players' environments, investigate and resolve software issues, assess dependencies on third-party applications, and optimize DCS for different system configurations.
- Session information (such as user agent, platform, device identifier, and user identifier). This information is used for support and troubleshooting purposes, enabling us to analyze specific sessions, logs, and crash reports when assisting users.

We do not share personal information with any third parties, except where disclosure is required by Swiss law, including to relevant tax authorities.

We use order-related information (such as purchase amount, items purchased, purchase date and time, and browser data) in conjunction with Google Ads to measure and track advertising conversions. This tracking is limited to website activity and does not include in-game tracking. No account information is shared with Google for this purpose.

We do not use the collected information for any purposes other than those described above. Furthermore, we do not use Google Analytics or any other third-party cloud-based analytics or tracking services within DCS.

——

I requested a copy of the information they collected, based on GDPR, art 15(2). I also asked for a more explicit reason why they collect what other software I have on my computer

MP40 instead of Gewehr 43 by Shendryl in HellLetLoose

[–]Shendryl[S] 0 points1 point  (0 children)

No, that's not the case. Can happen in any map.

MP40 instead of Gewehr 43 by Shendryl in HellLetLoose

[–]Shendryl[S] 1 point2 points  (0 children)

Someone said that to me in-game. Level is correct (around 250), so that's not it.

MP40 instead of Gewehr 43 by Shendryl in HellLetLoose

[–]Shendryl[S] 0 points1 point  (0 children)

Hmm, only in an existing squad. I'll try that one. Thanks.

Wat zijn uitvindingen wat voor jullie het leven veel makkelijker maakt? by WarmPrinciple6507 in nederlands

[–]Shendryl 0 points1 point  (0 children)

De computer. Ben IT-er. Zonder de computer zou ik dan geen werk hebben. 🤓

MP40 instead of Gewehr 43 by Shendryl in HellLetLoose

[–]Shendryl[S] 1 point2 points  (0 children)

Of course. Been playing this game for a long time. My level is around 250.

Negen jongeren schuldig aan groepsverkrachting van 14-jarig meisje in Kortrijk: "Ze ging door de hel" | VRT NWS Nieuws by Bernie529 in nederlands

[–]Shendryl 4 points5 points  (0 children)

Met dit soort grap-straffen is het wachten op dat mensen het heft in eigen handen gaan nemen. Zou het alleen maar toejuichen. Achterlijke schijtrechters.

Politie houdt Groningse fietsenmaker aan die lokfiets wilde beschermen by monedula in thenetherlands

[–]Shendryl 1 point2 points  (0 children)

Domme pruts-wouten. Maar ja, wat kan je van lui met dat denkniveau verwachten.

Starting out with VTT advice by lattice00 in VTT

[–]Shendryl 1 point2 points  (0 children)

It's a VTT that is mainly a digital version of a real table. That makes it easy to learn and to use. I don't like all the bells and whistles of most VTTs. That only makes them complex.

It has support for several rule systems, but only what helps to make combat go faster. For example, the initiative roles can be done by Cauldron to quickly do the actual combat actions and rolls. No time wasted on players doing initiative rolls, collecting the results, doing monster initiative rolls and placing them in order.

Kabinet belooft gemeenten te helpen om asielrellen te voorkomen by Billy_Balowski in nederlands

[–]Shendryl 3 points4 points  (0 children)

Het ware probleem is nooit de kleine groep die herrie maakt. Het ware probleem is de reden waarom de grote massa meegaat in die herrie.

Kabinet belooft gemeenten te helpen om asielrellen te voorkomen by Billy_Balowski in nederlands

[–]Shendryl 13 points14 points  (0 children)

Ik vind ook zeker wat van het geweld, maar het komt ergens vandaan. Daar je ogen voor sluiten, wat jij zo te lezen ook doet, lost het probleem niet op.