REALITY: Borrowing a TLS Handshake
REALITY does not disguise your traffic as a real TLS handshake, it serves an actual one. How that works, a working config, and the honest limits of the trick.
All the articles with the tag "tls".
REALITY does not disguise your traffic as a real TLS handshake, it serves an actual one. How that works, a working config, and the honest limits of the trick.
cert-manager makes Let's Encrypt automatic on Kubernetes, once. Then you scale, hit DNS-01 quirks, wildcard limits, and rate-limit walls. Here's the full survival guide.
TLS tunneling for legacy plaintext services, stunnel's X.509 cert model vs spiped's pre-shared key simplicity, and when each one actually wins.
TLS 1.3 explained without the PhD: faster handshakes, better ciphers, and how to actually configure Nginx and Caddy to use it.
Certificate pinning and HPKP explained: what they are, why HPKP destroyed itself, and modern alternatives like CAA records and Certificate Transparency.
Mutual TLS (mTLS) explained for mortals: how both sides authenticate, setting up step-ca for internal PKI, generating client certs, and configuring nginx with mTLS.
Advanced Caddy server configuration: wildcard certs, Caddyfile matchers, Docker label integration, rate limiting, forward auth with Authelia, and the JSON API.
Your proxy serves the leaf certificate and skips the intermediate, so half your clients fail. How to spot it, build the chain right, and keep renewals working.
Incomplete chains, bundles in the wrong order, and self-signed certs all read as untrusted. Diagnose with openssl s_client, then rebuild the chain properly.
Certificates expire silently and take the site with them. Check expiry with openssl, automate the check with cron or Uptime Kuma, and audit every cert.
Certificate pinning locks your app to a specific TLS cert so MITM attackers can't swap in a rogue CA, how it works and when to use it.