[saag] Re: pining a certificate/trust anchor
Deb Cooley <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CAGgd1Oe5ULp39-+NQ2BkLVQ5=N0QjPGD9ztyDZ8u57JfD1eqCQ@mail.gmail.com> |
Are you looking for RFC7469? Deb On Mon, Feb 10, 2025 at 1:52 PM Michael Richardson <[email protected]> wrote: > > Viktor Dukhovni <[email protected]> wrote: > > The trust anchors can be X.509 certificates or just public keys. So > it > > is possible to avoid needing a term like "pinning", which often > evokes > > fragile attempts to freeze the EE certificates of peers, and has been > > abandoned as too brittle. > > That's nice for postfix, and probably very relevant in SMTP. > > It does not apply everywhere, and sometimes the thing that needs to be > pinned > is a subordinate CA. Even if pinning is the wrong thing to do, having a > definition for what it is, is still useful if you need to say, "don't do > this" > > -- > Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting ) > Sandelman Software Works Inc, Ottawa and Worldwide > > > > > _______________________________________________ > saag mailing list -- [email protected] > To unsubscribe send an email to [email protected] > _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]