[saag] Re: pining a certificate/trust anchor

Yaron Sheffer <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
HPKP (RFC 7469) was effectively obsoleted by the industry, although the document remains current.

Daniel M. and myself authored an alternative (RFC 8672, Identity Pinning) which I’m still very fond of, but we never got any adoption in the real world.

Thanks,

Yaron

From: Deb Cooley <[email protected]>
Date: Monday, 10 February 2025 at 21:01
To: Michael Richardson <[email protected]>
Cc: [email protected] <[email protected]>
Subject: [saag] Re: pining a certificate/trust anchor

Are you looking for RFC7469?

Deb

On Mon, Feb 10, 2025 at 1:52 PM Michael Richardson <[email protected] > wrote:

Viktor Dukhovni <[email protected] > wrote:
> The trust anchors can be X.509 certificates or just public keys. So it
> is possible to avoid needing a term like "pinning", which often evokes
> fragile attempts to freeze the EE certificates of peers, and has been
> abandoned as too brittle.

That's nice for postfix, and probably very relevant in SMTP.

It does not apply everywhere, and sometimes the thing that needs to be pinned
is a subordinate CA. Even if pinning is the wrong thing to do, having a
definition for what it is, is still useful if you need to say, "don't do this"

--
Michael Richardson <[email protected] > . o O ( IPv6 IøT consulting )
Sandelman Software Works Inc, Ottawa and Worldwide

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.