3 ms·
> TLS libraries by default don't have this behavior. No, but the most popular one gives you just a callback and people end up using that to build their own ins
by ctz 2y ago
> TLS libraries by default don't have this behavior.
No, but the most popular one gives you just a callback and people end up using that to build their own insecure, weird strategies.
That's how we end up with things like "the certificate is valid if the issuer DN is this hardcoded string" (very common attempt at pinning an issuer), or "the certificate chain is valid if the chain contains this precise value" (this one, likely another failed attempt at pinning), or indeed the Hashicorp Vault vuln the other week which was roughly "the certificate is valid if it has the right AKID and serial number".