How bad is self-signed cert?
Kamal Mustafa

Kamal Mustafa @k4ml

About: Python/Django Developer at Kafkai.com, AI Writer for Generating Content, Built Exclusively for SEOs and Marketers.

Location:
Malaysia
Joined:
Aug 9, 2017

How bad is self-signed cert?

Publish Date: Jan 8 '19
4 1

How bad is you when it come to verifying a cert? People use cert from CA because browser already trusted the root cert that being used to sign the cert. So browser can do the verification. Using self-sign cert, you have to do the verification yourself. If it's only you to access the site, it's not that difficult. You have the cert, so you can add it to your browser to be trusted.

But if Joe, Anna and Foo also need to access the site, you have to "securely" hand over the cert to them. Probably still not much a problem as you can go and meet them in person. But imagine if there's 100 more, or 1000 more people need to access your site and you don't even know them. Now you start seeing a problem with using self-signed cert.

Comments 1 total

  • Tobias SN
    Tobias SNJan 8, 2019

    AFAIK, Let’s Encrypt provides free certificates, so there’s really no need to use a self-signed one.

Add comment