Skip to content

Conversation

@gelupa
Copy link
Collaborator

@gelupa gelupa commented Apr 1, 2021

For the use of pinsets, add the necessary condition under which it may cause a security problem.

For the description of chains of certificates, emphasis on the process of signature verifications, otherwise it may be ignored, since the whole paragraph focus on the pinning instead of signature verifications. It may cause an illusion that once the root CA is trusted, the certificate itself is enough for the verification, no need for a signature.

Fixed a typo.

under which it may cause a security problem.

For the description of chains of certificates, emphasis on the
process of signature verifications, otherwise it may be ignored.

Fixed a typo.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant