4 ms·
It's very clearly stated on the project's website: "sslip.io's primary purpose is to assist developers who need to test against valid SSL certs, not to safegua
by EngineerBetter 11y ago
It's very clearly stated on the project's website:
"sslip.io's primary purpose is to assist developers who need to test against valid SSL certs, not to safeguard content."
"Although there's no technical reason why you couldn't use the sslip.io SSL key and certificate for your commerce web, we strongly recommend against it: the key is publicly available; your traffic isn't secure."
- regecks 11y agoI wonder what that scenario even is, where you need a trusted certificate and are also (for some reason?) unable to use the mechanisms widely available in environments (either OS or language/API) to trust a testing certificate. This seems like a very silly service to operate, and as remarked by others, I guess the certificate will be revoked soon because the private key data is out there. Mostly surprised that this wasn't obvious to a company like Pivotal from the first moment.