Hacker News new | ask | show | jobs
by ThisIs_MyName 3436 days ago
Cert pinning ignores root certs. This is by design :(

>The Chromium browser disables pinning for certificate chains with private root certificates to enable various corporate content inspection scanners and web debugging tools (such as mitmproxy or Fiddler). The RFC 7469 standard recommends disabling pinning violation reports for "user-defined" root certificates, where it is "acceptable" for the browser to disable pin validation.

1 comments

The alternative would be no Chrome and/or Firefox at my workplace, and many others.