The EFF SSL Observatory
Posted Aug 6, 2010 15:30 UTC (Fri) by
JoeBuck (subscriber, #2330)
Parent article:
The EFF SSL Observatory
While it seems idiotic to make an SSL certificate for "localhost", I can understand why these get created. If your company has a machine on the internal net named payroll.mycompany.com, and you go to https://payroll.mycompany.com to file your timesheet, you might think that you can just type https://payroll. But your browser will then freak out: Alert! Alert! The host name doesn't match! That's because it's stupid: if the two names refer to the same IP address, this should not be an error. But it can lead IT people to quiet down their panicked non-technical VPs by making certs for every name a machine might be referred to as.
(
Log in to post comments)