[Bug 1895714] Re: Investigate and remove CA pinning

2022-01-17 Thread Launchpad Bug Tracker
[Expired for pollinate (Ubuntu) because there has been no activity for 60 days.] ** Changed in: pollinate (Ubuntu) Status: Incomplete => Expired -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1895714] Re: Investigate and remove CA pinning

2021-11-18 Thread Paride Legovini
Again, I think there are good reasons for pinning the certificate (I agree with myself of ~14 months ago). Even better would be to use a certificate generated by a private CA, so there's no third party that can generate a malicious certificate that is trusted by the client. We don't need a third

[Bug 1895714] Re: Investigate and remove CA pinning

2021-10-14 Thread Paride Legovini
** Changed in: pollinate (Ubuntu) Assignee: (unassigned) => Paride Legovini (paride) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1895714 Title: Investigate and remove CA pinning To manage

[Bug 1895714] Re: Investigate and remove CA pinning

2020-09-17 Thread Paride Legovini
For services that are not meant to be accessible by generic clients but that are instead bound to a specific client, then I think the best practice is to avoid the use of a public CA altogether, and rely on a private CA pinned in the client. This removes the (possibly-not-)trusted third party from

[Bug 1895714] Re: Investigate and remove CA pinning

2020-09-15 Thread Launchpad Bug Tracker
Status changed to 'Confirmed' because the bug affects multiple users. ** Changed in: pollinate (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1895714 Title:

[Bug 1895714] Re: Investigate and remove CA pinning

2020-09-15 Thread Robie Basak
Original design principle: https://blog.dustinkirkland.com/2014/02 /random-seeds-in-ubuntu-1404-lts-cloud.html """ Q: What about SSL compromises, or CA Man-in-the-Middle attacks? A: We are mitigating that by bundling the public certificates in the client. The pollinate package ships the

[Bug 1895714] Re: Investigate and remove CA pinning

2020-09-15 Thread Robie Basak
See also bug 1381359 - an example of a routine SRU updating the pin. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1895714 Title: Investigate and remove CA pinning To manage notifications about