5 ms·
Probably just an oversight, but I find it odd their (ZeroSSL) site does not use a certificate issued by their own CA, it is instead one of CloudFlare's SNI cert
by jamescun 6y ago
Probably just an oversight, but I find it odd their (ZeroSSL) site does not use a certificate issued by their own CA, it is instead one of CloudFlare's SNI certificates.
- mholt 6y agoThis is common for sites that are behind a TLS-terminating CDN. (They could still be using one between their origin and Cloudflare.) In general it doesn't matter who issues the certificate as long as they're trusted.
- snazz 6y agoIt's also worth mentioning that you can give Cloudflare your own certificate to use if you care what users see. I think this option might require one of the paid Cloudflare plans.
- jamescun 6y agoYou are correct, however CloudFlare does support supplying your own certificate, and I'd consider it an element of dogfooding to use their own CA on their own site.
- Xylakant 6y agoNote that you’d either need to hand cloudflare the private key for the cert or use their key server and run it on your infrastructure. You’ll also need to manage the certificates lifecycle. Unless you have a very compelling reason to do so, I doubt it’s worth the effort.