Definition · TLS & Certificates
What is Self-Signed Certificate?
A self-signed certificate is one where the subject and the issuer are the same key. It contains a valid public key and can encrypt a connection perfectly well, but nothing independent vouches for the identity it asserts. A client has no way to distinguish the genuine server’s self-signed certificate from an attacker’s, so browsers interrupt the connection with an interstitial warning and mail clients and API libraries typically refuse outright.
Encryption without authentication
The confidentiality provided by the TLS handshake is intact; what is missing is authentication. Without it, an on-path attacker can present their own self-signed certificate and, if the user clicks through the warning, read and modify everything — so the protection the encryption appeared to offer is not delivered. This is why “it is encrypted, the certificate just is not trusted” is not a reassuring statement about an internet-facing service.
Legitimate uses
Self-signed certificates are reasonable when trust is established some other way:
- Internal services where a private CA or the certificate itself is distributed to clients out of band
- Device and appliance bootstrapping, before a proper certificate can be installed
- Development environments, and test fixtures pinned to a known certificate
- Machine-to-machine links that use certificate pinning rather than CA validation
When they appear on an external attack surface
On the public internet, a self-signed certificate is usually an accident, and an informative one. It commonly marks a management interface, appliance, staging environment or database front end that was never intended to be reachable — the same population of hosts that tends to carry default credentials, exposed admin panels and unpatched CVEs. It also trains users to dismiss certificate warnings, which undermines the control everywhere else.
Certificate fields are worth reading rather than skipping: the subject name, organisation and validity dates on a self-signed certificate often name the product and internal hostname behind it, which is effectively free service fingerprinting. SurfaceLoop flags self-signed certificates alongside expiring certificates and weak TLS configuration.
Since publicly trusted DV certificates are free and automatable through ACME, there is rarely a good reason for an internet-facing service to serve one.
Related concepts
See certificate authority, certificate chain, security misconfiguration and TLS and certificates.