Skip to content

[Update] Running a Mail Server #5573

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 4 commits into from
Aug 25, 2022
Merged

[Update] Running a Mail Server #5573

merged 4 commits into from
Aug 25, 2022

Conversation

jschauma
Copy link
Contributor

The current text makes it seem as if using a self-signed certificate was a reasonable choice. With the proliferation of free, easy-to-renew certificates such as Let's Encrypt, it really seems that we can more strongly encourage good security practice instead of training people to deploy self-signed certs and click through certificate warnings, so this PR nudges users a bit more strongly to use a trusted CA.

@netlify
Copy link

netlify bot commented Jul 11, 2022

Deploy Preview for nostalgic-ptolemy-b01ab8 ready!

Name Link
🔨 Latest commit 8d377ba
🔍 Latest deploy log https://app.netlify.com/sites/nostalgic-ptolemy-b01ab8/deploys/630786d1d0e7270009e03b9f
😎 Deploy Preview https://deploy-preview-5573--nostalgic-ptolemy-b01ab8.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

@jfrederickson
Copy link
Contributor

The guide linked to here is specifically about purchasing and using a commercial TLS cert rather than using an ACME-provided cert.

Personally, I'd rather encourage people to use one of the free providers these days as you mention above, but it looks like the Let's Encrypt doc we have is considered deprecated in favor of a web-specific doc that doesn't quite apply here. Linking to something like that would be my preference, but linking to a deprecated doc would feel weird...

@jschauma
Copy link
Contributor Author

Yeah, I had specifically changed the wording from "purchase a signed certificate" to "request a trusted certificate" to avoid favoring a commercial solution. Changing the content of the linked doc at https://www.linode.com/docs/guides/obtain-a-commercially-signed-tls-certificate/ (which does include LE explicitly) is something that might make sense but it outside the intended scope of this PR.

@wildmanonline wildmanonline changed the title (more strongly) recommend using a trusted CA [Update] Running a Mail Server Aug 25, 2022
@wildmanonline wildmanonline self-assigned this Aug 25, 2022
@wildmanonline
Copy link
Collaborator

Thanks @jschauma. Tweaked your changes a bit and then added back in information on responsibly using self-signed certificates (internal-only usage really). This should go live later today.

@wildmanonline wildmanonline merged commit 35995d6 into linode:develop Aug 25, 2022
@jschauma
Copy link
Contributor Author

jschauma commented Aug 25, 2022 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants