I trust my own (or coworkers) certificates. It's a dev site for heavens sake.
Ever since, ssh-keygen all the way.
I trust my own (or coworkers) certificates. It's a dev site for heavens sake.
Ever since, ssh-keygen all the way.
As soon as you need some automation involving backend services or even just curl and some scripts, this gets tougher. (And please please don’t use `curl -k` to disable checks… if such scripts accidentally make their way to production, you may as well not use TLS at all.)
A certificate has two main functions: identity of the server and encryption. Not checking the chain leaves you with encryption, which is likely what your need.
A self-signed certificate is as good as any other when it comes to encryption.
You may trust the CA enough to not check further, but if you want to make sure that the endpoint you are talking with is the one you expect, you should check the identity of the certificate on the server. And it is the same for a self-signed certificate as from a CA-issued one.
And what you're saying about CA certs has no resemblance to reality. People don't look at certs by matching their public keys exactly to what they expect... they trust certificate authorities to make that determination for them. But again, `curl -k` does neither so I don't think your point applies regardless.
Then I thought, WTF am I doing?. I realized that I was making computers that would circumvent the world's security apparatus. Of course it won't hurt if I make no errors of practice or judgement but, am I really smart enough to handle highly radioactive material.
I ripped it all out. It makes me shudder thinking about it.
This becomes a nightmare, when the original admin in the org is gone long times ago.