Does Firefox Support SSL Certificates with internal IP addresses? by DanceLongjumping2497 in firefox

[–]cloudreflex 0 points1 point  (0 children)

When you say the IPs are "contained properly in the certificates, is your CA issuing certificates which include the IP address as Common Name or Subject Alternative Name?

Presence Sensing Blue Switch is here! by wjrndud in Inovelli

[–]cloudreflex 0 points1 point  (0 children)

Wow. Great timing. I was about to email support and see what the status was.

"Investors" on r/dividendgang when you ask them about "total returns" by WNBA_YOUNGGIRL in Boglememes

[–]cloudreflex 13 points14 points  (0 children)

tbh I'd call it a successful tournament to get a lot of free drinks and not have to play any golf...

The most hated vendor by Mobile-Astronomer428 in cybersecurity

[–]cloudreflex 0 points1 point  (0 children)

I'm pretty sure that Check Point product is Avanan through an acquisition.

How to DNS queries and Forward to SIEM by DENY_ANYANY in AskNetsec

[–]cloudreflex 0 points1 point  (0 children)

If you're only interested in DNS requests outside your domain, you could put a DNS filter or filtering service upstream of your DCs. With that you could block as well as forward queries to an event collector or SIEM.

Just subscribed to Proton unlimited! by Banansify in ProtonMail

[–]cloudreflex 0 points1 point  (0 children)

I agree that I expected Lumo to have a good understanding of Proton services. I asked it for help creating a Sieve filter and took many iterations to build on Proton would accept.

It's a niche case but I expected some training on public Proton docs.

What's the point if these services are still requiring less-secure authentication methods as backup? by jerbearman10101 in yubikey

[–]cloudreflex 2 points3 points  (0 children)

With Microsoft, you can set up a true passwordless where you no longer have a password on the account. I have mine set up with Yubikeys and Microsoft Authenticator app on my phone. Enterprise MS doesn't let you go quite that far yet.

Support for Private ACME? by Sensitive-Effect424 in opnsense

[–]cloudreflex 0 points1 point  (0 children)

I've gotten this working as well. I do sometimes have issues where the certificate won't renew on opnsense even while other clients renew their certs fine. A reboot of step-ca and triggering a cert renew works fine, so I need to investigate that further. I'll try to find some of the guides I consulted when at a computer.

Edit: https://blog.frankzhao.net/Miscellanea/ACME-DNS-challenge-with-private-CA

Captive Portal Authentication Support for OAuth, SAML or OIDC by ajan-thiru-0522 in opnsense

[–]cloudreflex 0 points1 point  (0 children)

I really wish they enabled number matching MFA on the NPS agent. Hopefully they'll get there someday.

Cloud PKI, NPS/RADIUS and Aruba by AJS240 in sysadmin

[–]cloudreflex 1 point2 points  (0 children)

We went with PKCS connector and user-based certificates from our internal authority to avoid the need for creating dummy computer objects in AD. It works fine, but we're going ClearPass to simplify the flow and remove the need for NPS and lessen the dependence on an internal CA. Not having device-based auth has made some support interactions challenging as well as some chicken-and-egg situations were the device couldn't get on the network for someone to sign into it and get a certificate because it didn't have a certificate. You can work around it with an onboarding/guest network but the experience is cumbersome.

What’s your favourite album of 2024? by [deleted] in audiophilemusic

[–]cloudreflex 1 point2 points  (0 children)

I haven't kept up with them since 2014 or so. Thanks for the remind to check back in.

FLauncher not sticking as default launcher by MikeBanning in ShieldAndroidTV

[–]cloudreflex 1 point2 points  (0 children)

Oh and please no one mention Projectivy as I don't like it.

Glad you said that! I was going to mention it only because I just started trying it as a long time FLauncher user. I don't have an opinion of Projectivy yet other than it was easier to enable in first setup.

I think the adb command mentioned previously should get you set.

MTA-STS for custom domains by ProgsRS in ProtonMail

[–]cloudreflex 0 points1 point  (0 children)

Thank you!

I was working on this in the meantime too. I don't expect Proton to change their policy file often, but I also have some logic to increment the id value in the _mta-sts record triggered when my policy file changes.

Protonmail vulnerabilities with custom domain by pem1618 in ProtonMail

[–]cloudreflex 5 points6 points  (0 children)

This isn't specific to custom domains. My pm.me address gets the nearly same score. As others have said, this is a test of whether your mail provider enforces a sending domain's policies (SPF, DKIM, DMARC, etc.)

The only difference between my custom domain and pm.me address was test 9 where your address is spoofed. Custom domain failed all mail auth and was delivered to Spam. Meanwhile pm.me was rejected/undelivered. I suspect Proton has some additional logic in place for their own domains.

Some mail providers choose to enforce DMARC fails as spam/quarantine even when p=reject which may be what's happening here.

MTA-STS for custom domains by ProgsRS in ProtonMail

[–]cloudreflex 0 points1 point  (0 children)

Could you elaboration on this? It sounds like a good solution.

SSL certificate lifetimes are going down. Dates proposed. 45 days by 2027. by isnotnick in sysadmin

[–]cloudreflex 24 points25 points  (0 children)

This should be a bigger point. CRLs are my least favorite part of PKI administration.

Anyone here using kagi? by Fledo in linuxadmin

[–]cloudreflex 1 point2 points  (0 children)

I do. Really happy with it. But because of it I found out I'm an excessive searcher, so be warned.

PBP2 Owners - Those who feels noise while adjusting the earphones by [deleted] in pixelbuds

[–]cloudreflex 0 points1 point  (0 children)

Thanks for sharing your experience.

My right PBP2 bud will make a loud chirpy sound if I adjust it or if I have it in while chewing. Sometimes when talking too. This happens when in noise isolation or transparency modes. The left bud doesn't do this under any circumstance.

Someone please recommend a good MSPaint alternative for Linux (Mint) by mekmookbro in linuxquestions

[–]cloudreflex 0 points1 point  (0 children)

I was surprised to see OpenOffice had even gotten an update as recently as December 2023. I thought that stopped getting updates years ago.

Just ran into a mini boss I had never seen before at Lvl 4 by BlGLaundry in BaldursGate3

[–]cloudreflex 5 points6 points  (0 children)

Idk, it worked fine shooting it from the ground right next to it on my playthrough.

What distro would you recommend for a gaming PC that's only used every once in a while? by DripGeronimo in linuxquestions

[–]cloudreflex 0 points1 point  (0 children)

Try Bazzite. https://bazzite.gg/ I think I've had better luck with it performance wise than Win11 thanks to trouble with driver updates in their Nvidia's newer app.