this post was submitted on 19 Sep 2024
51 points (89.2% liked)

Selfhosted

40329 readers
382 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 1 year ago
MODERATORS
51
submitted 2 months ago* (last edited 2 months ago) by [email protected] to c/[email protected]
 

After the arrest of Pavel Durov, I wanted to move from Telegram to something end-to-end encrypted. I know Signal is pretty good, but I think it is better to have our messages in my own server.

I have already looked in XMPP, but it required SSL certs and I did not have the mood to configure them.

Do you know any other selfhosted messaging service for a group of 4-5 friends, or an easy way to configure an XMPP server? Or shall I use Signal after all (I don't really care that much about being selfhosted, I just thought it would be more privacy friendly)?

UPDATE: I managed to set up an XMPP server using prosody with the SSL certs. We have been testing it with my friend and it seems to go well.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 27 points 2 months ago (11 children)

SSL certs is so easy with let's encrypt, that really shouldn't be a blocker.

If you want something easy I think you have your answer with Signal

[–] [email protected] 2 points 2 months ago* (last edited 2 months ago) (10 children)

I know, but for some reason my router does not let me access my domain (with duckdns) when connected to my network. So even if I get certs for the domain, I will not be able to access it. I have set up local DNS entries (with Pi-Hole) to point to my srrver, but I don't know if it possible to get certs for that, since it is not a real domain.

EDIT: Fixed it. (See reply for fix)

[–] [email protected] 3 points 2 months ago (1 children)

I have set up local DNS entries (with Pi-Hole) to point to my srrver, but I don't know if it possible to get certs for that, since it is not a real domain.

So long as your certs are for your fully qualified domain there's no problem. I do this, as do many people


mydoman.com is fully qualified, but on my own network I override the DNS to the local address. Not a problem at all


DNS is tied to the hostname, not the IP.

[–] [email protected] 3 points 2 months ago (1 children)

Can confirm, I do this as well for my local services (especially important for Jellyfin), I just point my local DNS server at my local IP and everything works perfectly.

[–] [email protected] 1 points 2 months ago (1 children)

Another fun trick you can play is to use a private IP on your public DNS records. This is useful for Jellyfin on Chromecast for instance


it uses 8.8.8.8 for DNS lookup (and ignores your router settings), so it wants a fully qualified domain name. But it has no problem accessing local hosts, so long as it's from 8.8.8.8's record.

[–] [email protected] 1 points 2 months ago (1 children)

I suppose, but then you're kind of screwed if you want to access Jellyfin outside of your network. I suppose you could use a VPN, but it's probably easier to just not use the Chromecast (or just accept that it's going to hit the WAN regardless).

[–] [email protected] 1 points 2 months ago (1 children)

Yeah I don't expose Jellyfin over the Internet, so it doesn't matter for me, and wouldn't work at all over WAN (unless VPN'd to home network).

Also, it's all reverse proxied, and there's nothing preventing having two Jellyfin hostnames, e.g., jf-local.mydomain.com and jf-public.mydomain.com.

[–] [email protected] 2 points 2 months ago (1 children)

Then you're all clear.

I personally want my Jellyfin to be on the WAN, and I have certain devices on my internal network VPN'd to my VPS, which exposes the services I want to access remotely. But if you don't need that, using the local addr in your DNS config totally works. Getting TLS certs will be complicated, but you don't need that anyway if everything is local or over a VPN.

[–] [email protected] 2 points 2 months ago

Getting TLS certs will be complicated

I just use Let's Encrypt with a wildcard domain


same certs for public and private facing domains. I'm sure this isn't best practice, but it's mostly just for me so I'm not too worried :)

load more comments (8 replies)
load more comments (8 replies)