[saag] Re: pining a certificate/trust anchor

Viktor Dukhovni <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
On Mon, Feb 10, 2025 at 01:52:18PM -0500, Michael Richardson wrote:
> 
> Viktor Dukhovni <[email protected]> wrote:
>     > The trust anchors can be X.509 certificates or just public keys.  So it
>     > is possible to avoid needing a term like "pinning", which often evokes
>     > fragile attempts to freeze the EE certificates of peers, and has been
>     > abandoned as too brittle.
> 
> That's nice for postfix, and probably very relevant in SMTP.
> 
> It does not apply everywhere, and sometimes the thing that needs to be pinned
> is a subordinate CA.   Even if pinning is the wrong thing to do, having a
> definition for what it is, is still useful if you need to say, "don't do this"

FWIW, Postfix supports trusting subordinate CAs, they become trust
anchors for the connection.  And you're not limited to a single
per-destination trust anchor, specify as many as you want or need.  Any
one of them is then sufficient to authenticate the (perhaps shorter
than otherwise) peer chain.

-- 
    Viktor.

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.