Skip to content

Provide better guidance on how to filter legitimate certificates #76

@AGWA

Description

@AGWA

Documentation/README should explain:

  • You can't compare certificate fingerprints because precertificates have a different fingerprint.
  • You don't want to compare serial numbers because malicious CAs could reuse the serial number.
  • Ideally you compare the TBS hash, but there are zero tools for computing this.
  • So comparing the public key fingerprint is the best bet.

Metadata

Metadata

Assignees

No one assigned

    Labels

    refinementAn improvement, but not a new feature

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions