What Is a Self-Signed Certificate? When Should You Use It?

· SSL Basics

A self-signed certificate is signed by the entity that created it rather than a trusted CA. It provides encryption but lacks third-party trust verification.

Why Browsers Don't Trust It

Browsers trust only certificates signed by pre-approved Root CAs. A self-signed certificate sits outside this chain — the browser can't verify the signer and shows a full-screen security warning. Users can click through, but this is unacceptable for any public-facing site.

Valid Use Cases

Development and testing: Test HTTPS-requiring apps on localhost or internal test servers. Zero cost, instant creation.

Internal network apps: Company intranets, internal tools, or admin panels accessible only to employees. You can add the cert as trusted on corporate devices.

IoT and embedded systems: Devices not directly internet-facing commonly use self-signed certificates.

VPN and secure tunnels: When access is limited to specific clients that have pre-validated the certificate.

Generating with OpenSSL

openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 365 -nodes

Never Use in Production

Public websites, APIs, email servers, and mobile app backends must use CA-signed certificates. Self-signed certs cause browser warnings, iOS ATS and Android Network Security Config will reject connections, and corporate browsers may block access entirely.

Visit the PekiSSL product page to find the right certificate for your needs.

All blog posts