4 ms·
As far as I know, browsers don't allow self-signed certificates on HTTP/3. This was mentioned by people in comments here, and quick google seems to confirm.
by taway1237 3y ago
As far as I know, browsers don't allow self-signed certificates on HTTP/3. This was mentioned by people in comments here, and quick google seems to confirm.
- Majestic121 3y agoYou cannot use a certificate that was not signed by a trusted CA, but nothing keeps you from creating your own CA, making it trusted locally, and using it to sign your cert
- mgaunard 3y agoNothing except convenience and compatibility with dozens of operating systems that might operate on the network. Can you even easily do it on Android? Without an Internet connection?
- koito17 3y ago> making it trusted locally That is precisely the problem. Most proprietary systems don't let you touch the trust store at all. Even "open" platforms like Android have been locking down the ability to do anything to the trust store.[1] With that said, if we assume the user is only using Google Chrome and not an alternative browser, then typing "thisisunsafe" on the TLS error page should let one elide trust store modifications entirely. I cannot guarantee this is the case for HTTP/3 since the reverse proxies I deal with still use HTTP/2. [1] https://httptoolkit.com/blog/android-14-breaks-system-certificate-installation/ https://httptoolkit.com/blog/android-14-breaks-system-certif...
- throwaway892238 3y agoOne might then ask: why not just let the user click a button in the browser to see the page, without jumping through all those hoops? How does increased human toil make it better? (Spoiler: it doesn't)
- throwjdn 3y ago[dead]