On 2007-01-25, at 8:43 PM, William M. Perry wrote:
Is there any way to use an XMLHttpRequest object to retrieve data from an
HTTPS URL when the server's certificate is not trusted for some reason
(self-signed certificates, expired certificate, etc).

I am running against a development server that has a self-signed certificate
(and its CN does not always equal the hostname it is running on).

Without a UI for prompting or an insecure mode flag you can add your CA key to the x509Anchors keychain - I use a dashboard widget which makes HTTPS requests for servers using an internal CA w/o problems this way.


