Can you use a wildcard ssl cert in 2x instead of the self signing one? If so, where do you install it? The server? The client? Both? Any assistance would be helpful.
If the Root certificate is not on the client's trusted.pem, the user would be asked if he wants to accepts the certificate. He can also select "Do not ask me again".