!cacbMwUwsLZ6GKac:nichi.co

NixOS 中文

2846 Members
72 Servers

Load older messages


SenderMessageTime
23 Apr 2024
@pokon548:bukn.ukBu Kun按三天签发倒还不错,因为 chromium 不检查这么短时间的证书的 oscp(07:53:47
@pokon548:bukn.ukBu Kun理论上可以加快访问速度07:53:57
@telegram_235473128:nichi.coLan Tiannginx可以验证mtls07:56:09
@telegram_235473128:nichi.coLan Tian应用本身监听127.0.0.107:56:22
@telegram_148111617:nichi.coYinfeng就是发起连接的那一方怎么处理07:56:50
@telegram_235473128:nichi.coLan Tian
In reply to Yinfeng
就是发起连接的那一方怎么处理
客户端是另一台机器上的nginx反代
07:57:13
@telegram_148111617:nichi.coYinfeng这么神奇的么07:57:22
@telegram_235473128:nichi.coLan Tian我的计划是用mtls替换掉现在的mesh vpn07:57:37
@telegram_148111617:nichi.coYinfeng那意思是应用只要 listen 就行了,本机的 nginx 直接向应用发起的连接么07:58:15
@telegram_235473128:nichi.coLan Tian
In reply to Yinfeng
那意思是应用只要 listen 就行了,本机的 nginx 直接向应用发起的连接么
07:58:21
@telegram_148111617:nichi.coYinfeng怎么感觉这意思还是要应用支持(07:58:46
@telegram_235473128:nichi.coLan Tian
In reply to Yinfeng
怎么感觉这意思还是要应用支持(
不,应用不用支持mtls,本机nginx到应用是无加密的
07:59:19
@telegram_148111617:nichi.coYinfeng是就是应用要改变实现方式的感觉07:59:32
@telegram_148111617:nichi.coYinfeng本来是向别的服务发起连接07:59:44
@telegram_148111617:nichi.coYinfeng现在不这么做了07:59:46
@telegram_235473128:nichi.coLan Tian毕竟服务端本机流量都被控制了就不用玩了07:59:47
@telegram_235473128:nichi.coLan Tianmtls处理的是反代的就近节点到实际后端节点这一段08:00:13
@telegram_789723741:nichi.coA1ca7raz |> escape
In reply to Lan Tian
我甚至想以小时为单位签发证书(
啊这
08:07:19
@gtrunsec:matrix.orgguangtao Yah: https://github.com/GTrunSec/omnibus/commit/858855504d2956cd310967a2944097049cffe953 09:25:32
@gtrunsec:matrix.orgguangtao * Yah: https://github.com/GTrunSec/omnibus/commit/858855504d2956cd310967a2944097049cffe953 => https://github.com/GTrunSec/omnibus/commit/858855504d2956cd310967a2944097049cffe953#diff-ef3b8a0e732926174bf319599bdc70f85159e6d54daaccd1c87d224e16290409R12 需要在meta命名attrs或者创建一个目标配置的xx文件就可以得到最干净的eval 09:26:39
@gtrunsec:matrix.orgguangtao((omnibus.pops.hive.setHosts hosts).setNixOSConfigurationsRenamer "myNixOSMachine" ).nixosConfigurations => host1.meta = { myNixOSMachine = {bee.system = "xxx"}}09:28:55
@gtrunsec:matrix.orgguangtao * Yah: https://github.com/GTrunSec/omnibus/commit/858855504d2956cd310967a2944097049cffe953 => https://github.com/GTrunSec/omnibus/commit/858855504d2956cd310967a2944097049cffe953#diff-ef3b8a0e732926174bf319599bdc70f85159e6d54daaccd1c87d224e16290409R12 只需要在meta命名attrs或者创建一个目标配置的xx文件就可以得到最干净的eval 09:29:07
@gtrunsec:matrix.orgguangtao * Yah: https://github.com/GTrunSec/omnibus/commit/858855504d2956cd310967a2944097049cffe953 => https://github.com/GTrunSec/omnibus/commit/858855504d2956cd310967a2944097049cffe953#diff-ef3b8a0e732926174bf319599bdc70f85159e6d54daaccd1c87d224e16290409R12 只需要在meta命名target attrs或者创建一个目标配置的xx文件就可以得到最干净的eval 09:29:17
@gtrunsec:matrix.orgguangtao * 语法如下: ((omnibus.pops.hive.setHosts hosts).setNixOSConfigurationsRenamer "myNixOSMachine" ).nixosConfigurations => host1.meta = { myNixOSMachine = {bee.system = "xxx"}}09:29:34
@gtrunsec:matrix.orgguangtao

如果你需要不同的renamer 并且导出不同的配置 语法如下

inherit (((omnibus.pops.hive.setHosts hosts).setNixOSConfigurationsRenamer "myNixOSMachine" ).setDarwinConfiguraitonsRenamer "xxxDarwin") nixosConfigurations darwinConfigurations colmeaHive wslConfiguratins 
09:36:37
@gtrunsec:matrix.orgguangtao *

如果你需要不同的renamer 并且导出不同的配置 语法如下

inherit (((omnibus.pops.hive.setHosts hosts).setNixOSConfigurationsRenamer "myNixOSMachine" ).setDarwinConfiguraitonsRenamer "xxxDarwin")  
nixosConfigurations 
darwinConfigurations 
colmeaHive 
wslConfiguratins;
09:36:59
@gtrunsec:matrix.orgguangtao *

如果你需要不同的renamer 并且导出不同的配置 语法如下

inherit (((omnibus.pops.hive.setHosts hosts)
  .setNixOSConfigurationsRenamer "myNixOSMachine" )
  .setDarwinConfiguraitonsRenamer "xxxDarwin")  
nixosConfigurations 
darwinConfigurations 
colmeaHive 
wslConfiguratins;
09:37:15
@gtrunsec:matrix.orgguangtao卖完币写完代码,一看币暴涨10%,心态炸裂了09:44:03
@rdfg77:kde.orglinsui 炒币的还在乎这点儿涨跌( 09:44:47
@rdfg77:kde.orglinsui 天天都是大起大落 09:45:04

There are no newer messages yet.


Back to Room ListRoom Version: 6