Live data from Hacker News

How to set up stress-free SSL on an OS X development machine

gist.github.com

11–20 of 23 posts

Re: How to set up stress-free SSL on an OS X development machine

#11

Only gripe is being told to match Dev with production ... And then develop on Mac OS. Virtual machines are a much cleaner and nicer way to do this. Setting up a wildcard SSL is similarly as simple, an you get the bonus of learning how to do it on a "real" (normal, more standard) server. Example setting up wildcard subdomain SSL cert (self-signed): https://serversforhackers.com/ssl-certs/

The development process is much less complicated when you only consider a single OS. The answer to: "How do I do this?" is always the same; a significant time/brain savings.

Re: How to set up stress-free SSL on an OS X development machine

#12

Only gripe is being told to match Dev with production ... And then develop on Mac OS. Virtual machines are a much cleaner and nicer way to do this. Setting up a wildcard SSL is similarly as simple, an you get the bonus of learning how to do it on a "real" (normal, more standard) server. Example setting up wildcard subdomain SSL cert (self-signed): https://serversforhackers.com/ssl-certs/

Having gotten more accustomed to the VM approach over the past year since I wrote this post, I agree.

Thanks for leaving your Gist up there describing the process, Jed. I do some work in VMs, but still found it very useful.

Re: How to set up stress-free SSL on an OS X development machine

#13
post #4
post #3

I didn't see self-signed certs as an alternative. Isn't that a common and reasonable approach?

This describes setting up a self-signed cert

I find it kind of ridiculous that making a self-signed cert is still that hard.

Re: How to set up stress-free SSL on an OS X development machine

#14

Only gripe is being told to match Dev with production ... And then develop on Mac OS. Virtual machines are a much cleaner and nicer way to do this. Setting up a wildcard SSL is similarly as simple, an you get the bonus of learning how to do it on a "real" (normal, more standard) server. Example setting up wildcard subdomain SSL cert (self-signed): https://serversforhackers.com/ssl-certs/

Having gotten more accustomed to the VM approach over the past year since I wrote this post, I agree.

Hi Jed, I was wondering what your VM box looks like? Any cool tools you would recommend?

Re: How to set up stress-free SSL on an OS X development machine

#16

Keychain Access makes creating a certificate authority very easy - you might as well just use that... Besides, I don't understand why you would choose not to trust the certificate, then click it and choose to trust it...

For the non-OS X crowd, XCA is a really simple GUI for managing your own CA. Just about everything I have that can use an SSL certificate has one that all of my machines trust.

http://xca.sourceforge.net/

Re: How to set up stress-free SSL on an OS X development machine

#18
Pow is a nice project for handling DNS resolution and forwarding a specific name to a service running on a non-standard port.

I've put Apache with a wildcard cert (& local CA) in front of it to handle SSL termination.

It's very similar to the technique from the article, but I've found the ability to serve requests on the default port to be convenient.

Re: How to set up stress-free SSL on an OS X development machine

#20
post #11

Only gripe is being told to match Dev with production ... And then develop on Mac OS. Virtual machines are a much cleaner and nicer way to do this. Setting up a wildcard SSL is similarly as simple, an you get the bonus of learning how to do it on a "real" (normal, more standard) server. Example setting up wildcard subdomain SSL cert (self-signed): https://serversforhackers.com/ssl-certs/

The development process is much less complicated when you only consider a single OS. The answer to: "How do I do this?" is always the same; a significant time/brain savings.

Also, if you develop for multiple clients, projects don't bleed into each other.

"Well, client X still uses PG 9.1, but I accidentally used a 9.3 feature, because thats what client Y uses."

Post reply on HN