[saag] Re: pining a certificate/trust anchor

Deb Cooley <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CAGgd1Oe5ULp39-+NQ2BkLVQ5=N0QjPGD9ztyDZ8u57JfD1eqCQ@mail.gmail.com>
Are you looking for  RFC7469?

Deb


On Mon, Feb 10, 2025 at 1:52 PM Michael Richardson <[email protected]>
wrote:

>
> Viktor Dukhovni <[email protected]> wrote:
>     > The trust anchors can be X.509 certificates or just public keys.  So
> it
>     > is possible to avoid needing a term like "pinning", which often
> evokes
>     > fragile attempts to freeze the EE certificates of peers, and has been
>     > abandoned as too brittle.
>
> That's nice for postfix, and probably very relevant in SMTP.
>
> It does not apply everywhere, and sometimes the thing that needs to be
> pinned
> is a subordinate CA.   Even if pinning is the wrong thing to do, having a
> definition for what it is, is still useful if you need to say, "don't do
> this"
>
> --
> Michael Richardson <[email protected]>   . o O ( IPv6 IøT consulting )
>            Sandelman Software Works Inc, Ottawa and Worldwide
>
>
>
>
> _______________________________________________
> saag mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.