• JWBananas@startrek.website
        link
        fedilink
        English
        arrow-up
        19
        ·
        1 年前

        Are you conflating self-signed and untrusted?

        Self-signed is fine if you have a trusted root deployed across your environment.

        • nickwitha_k (he/him)@lemmy.sdf.org
          link
          fedilink
          arrow-up
          6
          ·
          1 年前

          Correct. If using actual pki with a trusted root and private CA, you’re just fine.

          I took the statement to mean ad-hoc self-signed certs, signed by the server that they are deployed on. That works for EiT but defeats any MitM protection, etc.

    • KairuByte@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      3
      ·
      1 年前

      Hard disagree. As long as you have any machine with internet access it’s trivial, even more so if you can use DNS challenge.

    • KSP Atlas@sopuli.xyz
      link
      fedilink
      arrow-up
      1
      ·
      1 年前

      Also probably no sysadmin uses it, but the Gemini protocol requires the use of a self signed cert