@scottalanmiller @JaredBusch
I know my options, either Windows server acting as CA or OpenSSL in Linux, to be honest both routes was difficult to setup and requires a VM to be running at all times, to be the point I said screw it let them click the Advanced button and proceed to the site.
Cause encryption is occurring, with the self created ssl key + cert.
And our infrastructure is bit limited to be honest, so each VM has to be really needed to open one.
And the theoretical issue of 0.00001% of someone hijacking the server and do Man in the middle attack by routing to his SSL keys + cert is out of the park, if there is someone there with I.T skills I will pay him to help me.