Replace a self-signed certificate
tls-cert-selfsigned
A self-signed certificate is trusted by nobody, so visitors get a warning page and non-browser clients fail outright. Issue a real one.
Why this matters
Your site uses a self-signed certificate. Browsers show a warning page that blocks most visitors. Not exploitable — MitM requires users to actively bypass browser warnings, which modern browsers make very difficult.
Web servers
Nginx
- 1 Replace the self-signed certificate with one from a trusted CA
- 2 Let's Encrypt provides free certificates
bash
# Install Certbot and get a free certificate
sudo certbot --nginx -d example.comDoes your app still have this?
Scan your domain