[saag] Re: pining a certificate/trust anchor
Michael Richardson <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
Viktor Dukhovni <[email protected]> wrote: > The trust anchors can be X.509 certificates or just public keys. So it > is possible to avoid needing a term like "pinning", which often evokes > fragile attempts to freeze the EE certificates of peers, and has been > abandoned as too brittle. That's nice for postfix, and probably very relevant in SMTP. It does not apply everywhere, and sometimes the thing that needs to be pinned is a subordinate CA. Even if pinning is the wrong thing to do, having a definition for what it is, is still useful if you need to say, "don't do this" -- Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 515 B)
-----BEGIN PGP SIGNATURE----- iQFKBAEBCgA0FiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmeqSuIWHG1jcitpZXRm QHNhbmRlbG1hbi5jYQAKCRCAi3D73dDdZRETB/9EYCp9RPd2+fU3LA9Ee4F9P/vW IDXHR5snAfBs5cYOuvfNqslsCyTELh1mg64wY6nmyx/eCcJ3v59wilvT+15ltSvt eblZqVlWRNqr4LL/s+XkBFt8Fslx0k+OEfOt5swJ8suD2NDcu2R+9/+8KXcJVvJV Hm75idl5rAkGk+K5PhgVgHYwjFao1tyswcYeo/TiPDYs+MWFYhlFm/o53CsalVEt KnF9Q4EUOHRWl6M4XUT3CSPV0ibnaa3uYdNnMr4o6ETrB+tT8U8sHvsOkw3bedIX VszbonAHRqz0eCoOkq3sjbOlRia6CXyTgkKZpFUeBFMgIkW83rbjwyLsDJFf =NNd6 -----END PGP SIGNATURE-----