wraith

joined 1 month ago
[–] wraith@lemmy.ca 1 points 1 week ago (1 children)

I haven't set up the VPN yet. I am getting as much info as I can before I start any work. For the sake of this discussion, it would be a box on my network.

[–] wraith@lemmy.ca 1 points 1 week ago (3 children)

So I should just host it with an IP address instead of using the domain?

I hadn't thought to do that, at least not for anything other than short lived internal-network-only projects and tests. An IT guy in the company I work for advised me to just get a domain and host with it/subdomains to make it easier to manage if I wanted to host multiple services.

[–] wraith@lemmy.ca 1 points 1 week ago (5 children)

I will need it to be available via a VPN or other means, but it's not going to be any more public-facing than it has to be.

[–] wraith@lemmy.ca 1 points 1 week ago

I think you meant to reply to me! I actually do need it to be accessible externally, via a VPN or other means.

[–] wraith@lemmy.ca 1 points 1 week ago (1 children)

I am fairly new to self hosting and just wanted to know if this was a big enough deal that I should just get a domain that doesn't require HSTS preload. It's one thing to tinker with an IP address on a local network for some unimportant project; it's just intimidating to try it for real using a domain and hosting my own data.

I'm just a little nervous tbh. Thanks for the help!

[–] wraith@lemmy.ca 6 points 1 week ago (7 children)

Google requires HSTS preload for all of their domains. Charleston Road Registry (their subsidiary), enforces this by adding the TLD to the HSTS preload list.

Here is the Wikipedia link to the TLD. It's at the bottom.

[–] wraith@lemmy.ca 2 points 1 week ago* (last edited 1 week ago) (3 children)

Google is the registry that owns the rights to the TLD. They require all of the domains they control to have HSTS preload enabled.

22
submitted 1 week ago* (last edited 1 week ago) by wraith@lemmy.ca to c/selfhosted@lemmy.world
 

I have a domain that requires HSTS preload. I want to self host a few things using that domain (and subdomains), like nextcloud, pihole, and vaultwarden. How much of an issue is HSTS preload going to be if I do that? Will I need to set up a wildcard cert for everything? Or will it just work™️ because it's internal or traffic is through a VPN?

I can't find much about this so any help would be appreciated!