Certificates
Certificates are the single most reliable source of lost afternoons in this archive, and the six posts here cover a decade of it — the oldest is from 2016 and the newest from 2022.
The recurring theme is that a certificate is never just a certificate. It is a certificate plus whatever is validating it, and the validator is the part that changes. Chrome 58 stopped honouring commonName and every self-signed wildcard on my LAN went invalid overnight. A wildcard cannot be issued over an HTTP challenge at all, so getting one means handing a DNS API token to your ingress and deciding how you feel about that. A Spring Boot app behind a re-encrypt route wants a keystore, not the PEM files everything else wants.
There is also a Let's Encrypt renewal that died with a Python traceback, and OpenVPN certificates with a password added on top, which is the same underlying question: a credential is only as useful as the thing willing to accept it.
2016–2022 / 6 posts