• Anivia@feddit.org
    link
    fedilink
    arrow-up
    1
    ·
    2 days ago

    it’s just a file though right? Couldn’t you rip it from the real server?

    No, that’s not how TLS works. The certificate is not exposed to the internet unless the admins of the webserver are extremely incompetent. That would defeat the entire purpose, not only could you impersonate the server, but the encryption would also be futile since anyone would have access to the private key.