I think it’s a good idea, everyone should be automating this anyway.

  • cm0002@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    15 hours ago

    still want to make sure even on my private network I’m using valid certs. A lot of security departments require that too even if the device isn’t public facing.

    Is there a hard source with evidence that this is at all needed? Because there are a lot of things that “security departments” do that amount to security theater. Like forcing arbitrary password changes org wide.

    • ramble81@lemm.ee
      link
      fedilink
      English
      arrow-up
      3
      ·
      15 hours ago

      Regardless of “hard evidence” it’s still the company policy. How well does it go over if you try to say “well acktuslly…” when it comes to password changes.

      • cm0002@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        15 hours ago

        How well does it go over if you try to say “well acktuslly…” when it comes to password changes.

        Well, it went over easy, but I also gained the authority to implement or toss such policies when I took my job LMAO

        In any case, I was referring to the “my environment” part since it implied you had such authority and were just choosing to emulate policies of others, ofc I don’t mean to make decisions you don’t have the authority to. Hard evidence is hard evidence though, it does give you a leg to stand on should you propose such changes