309
submitted 2 years ago by [email protected] to c/[email protected]
you are viewing a single comment's thread
view the rest of the comments
[-] [email protected] 56 points 2 years ago* (last edited 2 years ago)

Why would anyone ever use self signed certs? Buy a cheap ass domain, and use LetsEncrypt to get a free cert.

[-] [email protected] 29 points 2 years ago

If it is for internal only, self signed is a lot easier.

[-] [email protected] -5 points 2 years ago

So is using "pass" as the password to all of your sensitive systems. Still not best, or even good practice.

[-] [email protected] 18 points 2 years ago

Are you conflating self-signed and untrusted?

Self-signed is fine if you have a trusted root deployed across your environment.

[-] [email protected] 4 points 2 years ago

Correct. If using actual pki with a trusted root and private CA, you're just fine.

I took the statement to mean ad-hoc self-signed certs, signed by the server that they are deployed on. That works for EiT but defeats any MitM protection, etc.

load more comments (3 replies)
load more comments (16 replies)
this post was submitted on 02 Oct 2023
309 points (93.5% liked)

Sysadmin

10179 readers
1 users here now

A community dedicated to the profession of IT Systems Administration

No generic Lemmy issue posts please! Posts about Lemmy belong in one of these communities:
[email protected]
[email protected]
[email protected]
[email protected]

founded 2 years ago
MODERATORS