Skip to content

Implement TBS certificate hash pinning and add tests for verification#507

Open
maederm wants to merge 1 commit into
AdguardTeam:masterfrom
maederm:feature/check-sdns-pinned-hashes
Open

Implement TBS certificate hash pinning and add tests for verification#507
maederm wants to merge 1 commit into
AdguardTeam:masterfrom
maederm:feature/check-sdns-pinned-hashes

Conversation

@maederm

@maederm maederm commented Jun 15, 2026

Copy link
Copy Markdown

Implement sdns stamp.Hashes validation. Currently the validation run next to the regular TLS certificate validation.

--insecure / opts.InsecureSkipVerify doesn't skip the pinning verification. The user can remove the certificate hashes from the stamp. Or I could add another flag to make it explicit if this is needed.

Fixes #506

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

TBS hashes from sdns stamp not verified for DoH

1 participant