Comment Re:SSL certs are both over-trusted and under-trust (Score 1) 194
look at openvpn team, they use selfsigned certs together with ca.crt, and y also can publish your site ca.crt on your web. you can show server and cliennt ip/domain on web page, so, you can100% avoid mitm attacks.