The university I work for uses Self-signed certs for everything but ssl. Apparently setting up properly signed certs is too expensive. And it's more effective to have the IT staff spend an inordinate amount of time convincing end-users that the warnings about invalid certs from various applications are nothing to worry about (I'm looking at you Andoid and OSX).