[saag] Re: pining a certificate/trust anchor

Michael Richardson <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
Viktor Dukhovni <[email protected]> wrote:
    > The trust anchors can be X.509 certificates or just public keys.  So it
    > is possible to avoid needing a term like "pinning", which often evokes
    > fragile attempts to freeze the EE certificates of peers, and has been
    > abandoned as too brittle.

That's nice for postfix, and probably very relevant in SMTP.

It does not apply everywhere, and sometimes the thing that needs to be pinned
is a subordinate CA.   Even if pinning is the wrong thing to do, having a
definition for what it is, is still useful if you need to say, "don't do this"

--
Michael Richardson <[email protected]>   . o O ( IPv6 IøT consulting )
           Sandelman Software Works Inc, Ottawa and Worldwide

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 515 B)
-----BEGIN PGP SIGNATURE-----

iQFKBAEBCgA0FiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmeqSuIWHG1jcitpZXRm
QHNhbmRlbG1hbi5jYQAKCRCAi3D73dDdZRETB/9EYCp9RPd2+fU3LA9Ee4F9P/vW
IDXHR5snAfBs5cYOuvfNqslsCyTELh1mg64wY6nmyx/eCcJ3v59wilvT+15ltSvt
eblZqVlWRNqr4LL/s+XkBFt8Fslx0k+OEfOt5swJ8suD2NDcu2R+9/+8KXcJVvJV
Hm75idl5rAkGk+K5PhgVgHYwjFao1tyswcYeo/TiPDYs+MWFYhlFm/o53CsalVEt
KnF9Q4EUOHRWl6M4XUT3CSPV0ibnaa3uYdNnMr4o6ETrB+tT8U8sHvsOkw3bedIX
VszbonAHRqz0eCoOkq3sjbOlRia6CXyTgkKZpFUeBFMgIkW83rbjwyLsDJFf
=NNd6
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.