2025-04-06, 09:31 PM
(This post was last modified: 2025-04-06, 11:40 PM by Balinus. Edited 2 times in total.)
Hello!
So, I have a security related question. Until now (mainly, since I first installed Jellyfin 3 weeks ago!), I used Tailscale to share my home Jellyfin server with my family. However, it is max 3 users and thus looked at the whole Caddy, duckdns, etc guides and successfully (and surprinsigly!) have a public domain name that points to my Jellyfin server.
I was wondering, how secure that is? I ran the testtls.com suite of tests, everything was green except a yellow msg about "Secure Renegociation- WARN- OpebSSL Handshake didnt succeed".
First, is this warning important? And secondly, what would be the best practice here? (see config below).
I use duckdns, then ports forwarding of 80 and 443 to internal IP. Caddy is configured to do the reverse proxy and with the config file of Caddy, I use the dns provider add-on for tls cert. I also have a cron script for dynamic dns with duckdns.
Perhaps a 3rd question: is Tailscale more secure or my config is quite enough? Ideally, I want something secure, but with more than 3 users.
So, I have a security related question. Until now (mainly, since I first installed Jellyfin 3 weeks ago!), I used Tailscale to share my home Jellyfin server with my family. However, it is max 3 users and thus looked at the whole Caddy, duckdns, etc guides and successfully (and surprinsigly!) have a public domain name that points to my Jellyfin server.
I was wondering, how secure that is? I ran the testtls.com suite of tests, everything was green except a yellow msg about "Secure Renegociation- WARN- OpebSSL Handshake didnt succeed".
First, is this warning important? And secondly, what would be the best practice here? (see config below).
I use duckdns, then ports forwarding of 80 and 443 to internal IP. Caddy is configured to do the reverse proxy and with the config file of Caddy, I use the dns provider add-on for tls cert. I also have a cron script for dynamic dns with duckdns.
Perhaps a 3rd question: is Tailscale more secure or my config is quite enough? Ideally, I want something secure, but with more than 3 users.