Headscale - Is it ok to use the default config (just editing the address/domain name)? will that be secure enough? Also which ports to I need to forward to my raspberry pi headscale server?

  • tack@feddit.org
    link
    fedilink
    English
    arrow-up
    7
    ·
    edit-2
    3 days ago

    That will work as long as your tls certificate is a wildcard cert (of the parent domain), otherwise your subdomains can be found via their certificate records. You probably know this, but caught me out initially, so figured I’ll mention it.

    • Jason2357@lemmy.ca
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 days ago

      Absolutely! I should have said both the dns and certificate are subdomain wildcards. Thanks for clarifying.