Skip to content

Tls

3 pages
  • curl --resolve and SNI: Testing Virtual Hosts Without /etc/hosts

    In Posts 455 words 3 min

    CurlTlsDevopsLinuxSecurity

    When you need to test a virtual host on a specific IP but don’t want to edit /etc/hosts — whether due to permissions, conflicts with other services, or just the habit of keeping the file clean — curl --resolve solves both problems at once: it …

    When you need to test a virtual host on a specific IP but don’t want to edit /etc/hosts — whether due to permissions, conflicts with other services, or just the habit of keeping the file clean — curl --resolve solves both problems at once: it …

  • OpenSSL: TLS Certificate Verification and Parsing in CLI

    In Posts 911 words 5 min

    LinuxTlsSecurityCliOpenssl

    Certificates expiring on prod at the worst moment — a familiar story. OpenSSL answers TLS certificate questions faster than any marketplace checker. Here are the key scenarios without the fluff. Basic Certificate Parsing The first command for any …

    Certificates expiring on prod at the worst moment — a familiar story. OpenSSL answers TLS certificate questions faster than any marketplace checker. Here are the key scenarios without the fluff. Basic Certificate Parsing The first command for any …

  • Trusting a custom CA: system store, browsers, and CLI

    In Posts 1048 words 5 min

    TlsPkiCertificatesDevopsSecurity

    A TLS error that says the certificate is untrusted almost never means the certificate is “broken”. The trust anchor is in the wrong store. curl, openssl, Git, Python, and the browser are different clients. Some keep their own root lists. Updating the …

    A TLS error that says the certificate is untrusted almost never means the certificate is “broken”. The trust anchor is in the wrong store. curl, openssl, Git, Python, and the browser are different clients. Some keep their own root lists. Updating the …