Welcome to Doom9's Forum, THE in-place to be for everyone interested in DVD conversion.

Before you start posting please read the forum rules. By posting to this forum you agree to abide by the rules.

 

Go Back   Doom9's Forum > Announcements and Chat > General Discussion
Register FAQ Calendar Today's Posts Search

Reply
 
Thread Tools Search this Thread Display Modes
Old 13th February 2012, 21:11   #1  |  Link
Chumbo
Registered User
 
Chumbo's Avatar
 
Join Date: Feb 2005
Posts: 585
Doom9.org self-signed certificate

Quote:
Originally Posted by CruNcher View Post
Is the link supposed to be a secured link? Just noticed it and tried it and looks like has a bogus certificate?
__________________
Chumbo
Chumbo is offline   Reply With Quote
Old 13th February 2012, 21:19   #2  |  Link
LoRd_MuldeR
Software Developer
 
LoRd_MuldeR's Avatar
 
Join Date: Jun 2005
Location: Last House on Slunk Street
Posts: 13,248
Quote:
Originally Posted by Chumbo View Post
Is the link supposed to be a secured link? Just noticed it and tried it and looks like has a bogus certificate?
That obviously is a self-signed certificate.

If you don't want to pay a CA for a "real" certificate or if you just want to have something for testing your server, creating a self-signed certificate is reasonable.

For obvious reasons the web-browser cannot check the validity of a self-signed certificate, because it was not signed by one of the trusted CA's whose root-certificate is known.

Anyway, you can still check the fingerprint of the self-signed certificate yourself and then it can be just as "secure" as a certificate that was signed by some trusted CA...

(Of course somebody would have to tell you the correct fingerprint of the certificate - either "offline" or through some tamper-proof channel - so you can verify it)
__________________
Go to https://standforukraine.com/ to find legitimate Ukrainian Charities 🇺🇦✊

Last edited by LoRd_MuldeR; 14th February 2012 at 00:53.
LoRd_MuldeR is offline   Reply With Quote
Old 13th February 2012, 21:40   #3  |  Link
Midzuki
Unavailable
 
Midzuki's Avatar
 
Join Date: Mar 2009
Location: offline
Posts: 1,480
Anyway, it seems Cruncher likes to surf on these forums through https instead of plain http. Only recently I've noticed that ALL of his links to a post on doom9.org use https.
Midzuki is offline   Reply With Quote
Old 14th February 2012, 03:07   #4  |  Link
mpucoder
Moderator
 
Join Date: Oct 2001
Posts: 3,530
The big difference with self-signed and certified is about doing business with a site - can they be trusted to process a credit card order, are they legitimate, etc. For that you would want a site that has been certified. However any https connection is encrypted, therefore protected from sniffers (electronic eavesdropping).
mpucoder is offline   Reply With Quote
Old 14th February 2012, 04:44   #5  |  Link
Chumbo
Registered User
 
Chumbo's Avatar
 
Join Date: Feb 2005
Posts: 585
Quote:
Originally Posted by LoRd_MuldeR View Post
That obviously is a self-signed certificate.

If you don't want to pay a CA for a "real" certificate or if you just want to have something for testing your server, creating a self-signed certificate is reasonable.

For obvious reasons the web-browser cannot check the validity of a self-signed certificate, because it was not signed by one of the trusted CA's whose root-certificate is known.

Anyway, you can still check the fingerprint of the self-signed certificate yourself and then it can be just as "secure" as a certificate that was signed by some trusted CA...

(Of course somebody would have to tell you the correct fingerprint of the certificate - either "offline" or through some tamper-proof channel - so you can verify it)
Yeah, I shouldn't have used the word "bogus" but I was more curious than anything else. Your explanation is nicely done to help others who may not be sure about the self-signed certificate. Thanks a lot.
__________________
Chumbo
Chumbo is offline   Reply With Quote
Old 14th February 2012, 12:51   #6  |  Link
LoRd_MuldeR
Software Developer
 
LoRd_MuldeR's Avatar
 
Join Date: Jun 2005
Location: Last House on Slunk Street
Posts: 13,248
Quote:
Originally Posted by mpucoder View Post
The big difference with self-signed and certified is about doing business with a site - can they be trusted to process a credit card order, are they legitimate, etc. For that you would want a site that has been certified. However any https connection is encrypted, therefore protected from sniffers (electronic eavesdropping).
I don't want to be picky, but that's not the whole truth. An encrypted connection is pretty much useless as long as you can't determine with whom you are making an encrypted connection! As long as the certificate has not been verified, you may be making an encrypted connection with the Doom9 server - but you may be making an encrypted connection with some attacker, who is acting as a "man in the middle" and who just pretends to be the Doom9 server, just as well. In the latter case, you would be using an "secure" encrypted HTTPS connection, yes, but the end-point of that connection is the attacker's computer. Bummer!

That's why certificates need to be verified and why an encrypted connection without an approved certificate is pointless. Still, a self-signed certificate can be just as "genuine" and "secure" as one that was signed by a trusted CA. The only difference is, that the self-signed one has to be verified by hand (by checking its fingerprint). It simply can not be verified automatically by the PKI. After all, all the "root" certificates your browser contains are self-signed too...

BTW: After the recent incidents, I would trust a self-signed certificate (which you have verified yourself!) much more than one that was signed by a CA
__________________
Go to https://standforukraine.com/ to find legitimate Ukrainian Charities 🇺🇦✊

Last edited by LoRd_MuldeR; 14th February 2012 at 16:25.
LoRd_MuldeR is offline   Reply With Quote
Old 14th February 2012, 19:31   #7  |  Link
amtm
Guest
 
Posts: n/a
One of the big issues that Chrome has, though I'd assume other brower's might as well, is that the self-signed cert doesn't match the URL of this site. Even after installing it in the trusted root store, it will still complain due to that reason. Luckily it can be bypassed but whenever Chrome is closed and then opened again it will display the huge warning page whenever you want to come back here via https.
  Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 16:16.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.