3 ms·
IME when people start using self signed certificates they trust anything that is presented, with no pinning. That means that so long as you MITM it with somethi
by uid65534 2y ago
IME when people start using self signed certificates they trust anything that is presented, with no pinning. That means that so long as you MITM it with something with it's own self signed cert it will work just fine.
- PeterisP 2y agoThis is why "self-signed" is a misleading term, as it means both literally self-signed, as in, "we have added root of trust that we control and our devices trust only certificates signed by ourselves, as cryptographically verified", and also "our devices trust any certificate signed by anyone and ignore errors", and doesn't make a distinction between these two very different cases. Especially for internal server-to-server connections there shouldn't be any security weaknesses in a fully self-signed architecture where the same scripts that deploy the certificates will also deploy the configuration on other servers specifying that this is the only thing that should be trusted.