[saag] Re: pining a certificate/trust anchor
Yaron Sheffer <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
HPKP (RFC 7469) was effectively obsoleted by the industry, although the document remains current. Daniel M. and myself authored an alternative (RFC 8672, Identity Pinning) which I’m still very fond of, but we never got any adoption in the real world. Thanks, Yaron From: Deb Cooley <[email protected]> Date: Monday, 10 February 2025 at 21:01 To: Michael Richardson <[email protected]> Cc: [email protected] <[email protected]> Subject: [saag] Re: pining a certificate/trust anchor Are you looking for RFC7469? Deb On Mon, Feb 10, 2025 at 1:52 PM Michael Richardson <[email protected] > wrote: Viktor Dukhovni <[email protected] > wrote: > The trust anchors can be X.509 certificates or just public keys. So it > is possible to avoid needing a term like "pinning", which often evokes > fragile attempts to freeze the EE certificates of peers, and has been > abandoned as too brittle. That's nice for postfix, and probably very relevant in SMTP. It does not apply everywhere, and sometimes the thing that needs to be pinned is a subordinate CA. Even if pinning is the wrong thing to do, having a definition for what it is, is still useful if you need to say, "don't do this" -- Michael Richardson <[email protected] > . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected] _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]