4 ms·
Can you pin leaf certificates? Quoting https://developer.mozilla.org/en/docs/Web/Security/Public_Key_Pinning https://developer.mozilla.org/en/docs/Web/Security
by maggit 11y ago
Can you pin leaf certificates?
Quoting https://developer.mozilla.org/en/docs/Web/Security/Public_Key_Pinning https://developer.mozilla.org/en/docs/Web/Security/Public_Ke...:
> Firefox (and Chrome) disable Pin Validation for Pinned Hosts whose validated certificate chain terminates at a user-defined trust anchor (rather than a built-in trust anchor).
I understand this as "when using HPKP, you have to pin a CA certificate, not your site's leaf certificate". If this understanding is correct, I think your comment about HPKP is wrong and it is in fact a good idea to use a CA you find trustworthy and pin its certificate. Agree?
- lmm 11y agoNo, that phrasing is saying that custom CA certificates override pinning (e.g. for corporate MITM proxies).
- _ikke_ 11y agoSorry, accidentally down-voted.
- pfg 11y agoIt's my understanding that you can pin to any certificate in your chain, but if a server presents a certificate that leads to a user-defined trust anchor (i.e. your typical corporate MitM proxy cert), no HPKP check is performed.