Definition

Security technique where TLS clients accept only specific certificate hashes or CA chains — bypassing standard PKI trust stores to prevent rogue CA issuance. Common in proxy/VPN tools replacing allowInsecure configurations.

Key Points

  • 2026-10-04: xray-core pinnedPeerCertSha256 bypass allowed MITM when pinning CA + empty ServerName (IP-based gRPC/Hy2) (2026-10-04-xray-core-github-advisory-ghsa)
  • Go crypto/tls: InsecureSkipVerify=true required when custom pinning used; hostname verification depends on ServerName being set
  • Pinning a public CA (not leaf cert) is dangerous — attacker can issue valid leaf for own domain through same CA
  • Silent security fixes without advisory erode trust in circumvention tooling used by privacy-conscious users

Sources