Lab notebook
Standing up a local certificate authority
Internal HTTPS shouldn't mean clicking through a browser warning every time
you hit a service on your own network. That's the itch that finally got
scratched this week: a self-signed root certificate authority for the lab,
with a daily renewal timer so the root never quietly expires on me.
Alongside the CA itself, I wrote a small script to issue per-service leaf
certificates — point it at a service, get back a cert signed by the root,
done. No more one-off openssl incantations copy-pasted from three
projects ago.
The last piece was a small status page: somewhere to download the root
certificate and get per-platform instructions for trusting it, so any new
device on the network can be onboarded in a couple of minutes instead of
me remembering the steps from memory.
And then, because I couldn't resist the symmetry: I made the download site
itself serve over HTTPS, using a certificate issued by its own CA. Dogfooding,
but literally — the CA site trusts the CA.
It took a couple of passes to get the renewal timing right, but it's been
quietly reissuing certs in the background ever since, which is exactly the
point.