Definition
Security technique where TLS clients accept only specific certificate hashes or CA chains — bypassing standard PKI trust stores to prevent rogue CA issuance. Common in proxy/VPN tools replacing allowInsecure configurations.
Key Points
- 2026-10-04: xray-core
pinnedPeerCertSha256bypass allowed MITM when pinning CA + empty ServerName (IP-based gRPC/Hy2) (2026-10-04-xray-core-github-advisory-ghsa) - Go crypto/tls:
InsecureSkipVerify=truerequired when custom pinning used; hostname verification depends onServerNamebeing set - Pinning a public CA (not leaf cert) is dangerous — attacker can issue valid leaf for own domain through same CA
- Silent security fixes without advisory erode trust in circumvention tooling used by privacy-conscious users