3 ms·
> Self-signed certificates don't work at all on the public Internet, but they're just fine for internal resources, as long as you can somehow pin them. Yes sel
by sehrope 13y ago
> Self-signed certificates don't work at all on the public Internet, but they're just fine for internal resources, as long as you can somehow pin them.
Yes self-signed certificates don't work for web servers/browsers but they work great for *aaS providers.
A lot of DBaaS providers sign their server SSL certificates with an internal self-signed CA (ex: AWS for MySQL RDS[1]). You just need to retrieve the CA certificate over a secure channel (ex: HTTPS) and save it along with the rest of the DB config for your app (user/pass/host/port) so it's pinned.
This is arguably better than using the browser-CA chain as the service provider itself would need to be complicit in compromising it (vs a malicious trusted root issuing a fraudulent trusted cert for the remote server).
[1]: http://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/CHAP_MySQL.html#MySQL.Concepts.SSLSupport http://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/CHAP_M...
- tptacek 13y agoJust a nit: those aren't self-signed certificates; those are certificates signed by an internal CA. A self-signed certificate is a standalone entity.