bazcurtis,
@bazcurtis@mastodon.social avatar

I am going to try to setup Let’s Encypt on my Home Assistant server this weekend.

This article looks very helpful.

https://theprivatesmarthome.com/how-to/enable-https-using-lets-encrypt-in-home-assistant/

spitfire,
@spitfire@mastodon.social avatar

@bazcurtis The guide you’ve described here seems to expose your HA to the internet. I’d take additional precautions and use multi factor authentication for accounts on that instance, and clodflared (which can block some unwanted traffic) instead of just SSL port exposed to the internet.

bazcurtis,
@bazcurtis@mastodon.social avatar

@spitfire If it needs external internet I won’t do it.

spitfire,
@spitfire@mastodon.social avatar

@bazcurtis This guide seems like it does just that. Can you try connecting to your HA address (the one set for Dynamic DNS) using cellular on your phone?

bazcurtis,
@bazcurtis@mastodon.social avatar

@spitfire None of my Home Assistant instances are public facing. Nothing is exposed.

spitfire,
@spitfire@mastodon.social avatar

@bazcurtis Ok, if they’re communicating directly, then how are they doing it if they’re not on the same local network then?

bazcurtis,
@bazcurtis@mastodon.social avatar

@spitfire I really don't know. I can't see how it works either, but I am going to try. I don't expect it to work to be honest, but we will see 😀

bazcurtis,
@bazcurtis@mastodon.social avatar

@spitfire So it seems it uses ZeroTier.

spitfire,
@spitfire@mastodon.social avatar

@bazcurtis Yup, so that’s a VPN ;) I guess that would also let you connect your phone remotely to it if you needed to.

bazcurtis,
@bazcurtis@mastodon.social avatar

@spitfire I am not going to use a service I know nothing about. I will just have to go to Mum’s which is a 10 minute walk away 🤣

spitfire,
@spitfire@mastodon.social avatar

@bazcurtis Man, it’s just an app you can install on your phone that can connect to your server. You can be away from home at some point and may need to look something up. It is a pretty secure way of doing it, so why not use it if you’ve already set it up (and already in use for other stuff)?;)

bazcurtis,
@bazcurtis@mastodon.social avatar

@spitfire I have never heard of ZeroTier. This was more of a pet project. I don’t really need to do it. I will do some ZeroTier research. Home Assistant gives the add-on 4/8 on their security score.

spitfire,
@spitfire@mastodon.social avatar

@bazcurtis Well, you’re already using it anyway - so better check if you’re ok with it :)
Another similar solution which would give you pretty much the same functionality is Tailscale.

bazcurtis,
@bazcurtis@mastodon.social avatar

@spitfire I did see that. I think I will give a go. Not sure I will have time today. It will have wait for another week. I appreciate all the feedback and pointers.

spitfire, (edited )
@spitfire@mastodon.social avatar

@bazcurtis Probably a good idea. Self hosted VPN (which you’re already running) is pretty handy sometimes.

bazcurtis,
@bazcurtis@mastodon.social avatar

@spitfire I did it in the end. It was very quick and quite easy. I couldn’t leave it.

spitfire, (edited )
@spitfire@mastodon.social avatar

@bazcurtis I’m running Tailscale (used OpenVPN, tinc and regular Wireguard- which Tailscale is using for the tunnel) on my routers (old apt., house, mom’s home) so I can access anything from anywhere, between these locations and individual devices connected to the same tailnet (my tailscale network) - like my iPhone or MacBook wherever I am. This does not technically open services inside of these locations to the internet.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • homeassistant
  • ngwrru68w68
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • InstantRegret
  • GTA5RPClips
  • Youngstown
  • everett
  • slotface
  • rosin
  • osvaldo12
  • mdbf
  • kavyap
  • cubers
  • JUstTest
  • modclub
  • normalnudes
  • tester
  • khanakhh
  • Durango
  • ethstaker
  • tacticalgear
  • Leos
  • provamag3
  • anitta
  • cisconetworking
  • megavids
  • lostlight
  • All magazines