Conversation

Did all the good DANE TLSA record checkers all go away? All the ones I can find are caching results, either the report, or the DNS queries, so they are near useless for fixing/debugging your records.
2
2
Replying to
Thanks. Their results are a little bit critical though. Just because my secondary doesn't have IPv6 it says: Too bad! Your website is not reachable for visitors using a modern internet address (IPv6), or improvement is possible. Same with HTTPS.
2
Replying to
I just generate them locally. ECDSA: openssl ec -in /etc/letsencrypt/live/domain.com/privkey.pem -outform der -pubout | openssl dgst -sha256 -hex RSA: openssl rsa -in /etc/letsencrypt/live/mail.grapheneos.org/privkey.pem -outform der -pubout | openssl dgst -sha256 -hex
2
Show replies