From: Hiroshi Nakamura Date: 2011-04-20T11:19:29+09:00 Subject: [ruby-core:35820] Re: Patch to Net::HTTP to allow overriding SSL certificate hostname verification On Sat, Apr 16, 2011 at 09:21, Patrick Higgins wrote: > I have a need to connect to an https server using Net::HTTP which > (incorrectly) returns a wildcard certificate that matches close enough > for me that I wish to allow it without completely disabling peer > verification, which is too insecure for my needs. I would really like > to see the server fix their problem, but as a client my hands are > tied. RFC2818 says; Names may contain the wildcard character * which is considered to match any single domain name component or component fragment. E.g., *.a.com matches foo.a.com but not bar.foo.a.com. so https://android.apis.google.com/ cannot use a wildcard cert for '*.google.com'. Can you ask Google to fix it? Accessing https://android.apis.google.com/ with Google Chrome (error page) should be a good evidence. :) Aside from this, making it configurable could sound acceptable but I think it's too much for saving mis-configured servers. Regards, // NaHi