1 point
*

Why would anyone ever use self signed certs? Buy a cheap ass domain, and use LetsEncrypt to get a free cert.

permalink
report
reply
1 point

Not pictured: Using a CA to properly administer certs because self-signed certs are not secure.

permalink
report
reply
0 points

How are they not secure? You are still doing TLS to the service, maybe they have weak keys but it is still a form of secure connection.

permalink
report
parent
reply
0 points

Certs do more than encryption in transit. They are also used for protection against MitM and authentication. Self-signing removes the ability to verify a cert’s authenticity.

permalink
report
parent
reply
0 points

That’s bullshit. You are the one who issued the cert. You can add it to your list of trusted certificates. You just have to check that this is the right certificate.

Your man in the middle scare comes from users who ignore cert warnings and continue without checking anything.

permalink
report
parent
reply

Sysadmin

!sysadmin@lemmy.world

Create post

A community dedicated to the profession of IT Systems Administration

No generic Lemmy issue posts please! Posts about Lemmy belong in one of these communities:
!lemmy@lemmy.ml
!lemmyworld@lemmy.world
!lemmy_support@lemmy.ml
!support@lemmy.world

Community stats

  • 423

    Monthly active users

  • 91

    Posts

  • 322

    Comments