3 ms·
You don't really mean self-signed, do you? I'm a doctor. Here's my diploma. I created and signed it myself. But trust me, I really am a doctor. I hope you
by trippy_biscuits 13y ago
You don't really mean self-signed, do you? I'm a doctor. Here's my diploma. I created and signed it myself. But trust me, I really am a doctor. I hope you really meant that you use an internal CA that issues certs and that you trust that CA instead.
- tptacek 13y agoI mean self-signed, if you pin the certs. I also mentioned internal CAs.
- snowwrestler 13y agoSelf-signed certs work for internal infrastructure because you control the full chain of trust. One server issues the "diploma" and the other checks it, but they're both your servers, so the trust is predetermined. Internal CA is more about expediency than anything else. It's just easier to manage trust between a lot of servers that way than by manually exchanging self-signed certs across all the permutations.