4 ms·
(Untested idea) I'd suggest creating your own Root CA with an expire-date far in the future. Install it's public key as a trusted certificate and all derived ce
by ThermalCube 5y ago
(Untested idea) I'd suggest creating your own Root CA with an expire-date far in the future. Install it's public key as a trusted certificate and all derived certificates should not prompt any issues anymore
- spyke112 5y agoPlease don't. I've been in orgs doing this and it sucks. There seems to just be to many edge cases, and to many custom scripts for setup.
- coding_unit_1 5y agoThat's not untested insofar as that's how I've always seen self-signed certs managed in an org.
- PinguTS 5y agoThen far in the future, when your own Root CA expires, then there comes all the trouble to update all the services/devices to trust the new Root CA. This becomes a nightmare, when the original admin in the org is gone long times ago.
- tqwhite 5y agoI did this on my workstation. I used it for a short while. Then I realized that I was actually putting a thing into the world that circumvents the entire security infrastructure of the world. Then I needed to do it for a server. Local only. Never production. Then I thought, WTF am I doing?. I realized that I was making computers that would circumvent the world's security apparatus. Of course it won't hurt if I make no errors of practice or judgement but, am I really smart enough to handle highly radioactive material. I ripped it all out. It makes me shudder thinking about it.