Certificate Pinning
Certificate pinning is a security technique where an application remembers or restricts which certificate, public key, or CA should be accepted for a specific server.
Normally, a client trusts any valid certificate chain that leads to a trusted CA. With certificate pinning, the client adds an extra rule: the certificate or public key must also match the pinned value.
Certificate pinning can help reduce the risk of trusting a wrongly issued or fraudulent certificate. However, it must be used carefully because incorrect pinning can break real users if certificates are rotated or replaced.
Certificate pinning is most suitable when:
The app controls both sides: The same organization controls the client app and server.
Certificate rotation is planned: Backup pins and renewal processes are managed properly.
The risk justifies it: The application has a strong reason to restrict trust beyond normal PKI validation.
For many normal websites, standard PKI validation with properly issued TLS certificates is preferred over manual pinning because bad pin management can cause outages.
PKI, CA, Chain of Trust, and Pinning
Concept | Main Purpose |
|---|---|
Certificate Authority | Issues trusted digital certificates |
PKI | Manages certificates, keys, trust, and revocation |
Chain of Trust | Verifies a certificate path back to a trusted root |
Certificate Pinning | Restricts trust to specific certificates, keys, or CAs |
These concepts work together to solve the trust problem in public key cryptography. Encryption protects data, but PKI helps verify that the encryption is happening with the correct party.
Why Certificate Pinning Matters
Certificate pinning adds an extra layer of protection beyond normal certificate validation. Even if an attacker obtains a fraudulent certificate from a trusted CA, a pinned application may reject it because it does not match the expected certificate or public key.
This can help protect users from:
Misissued certificates
Compromised certificate authorities
Certain man-in-the-middle attacks
Unauthorized certificate replacement
Because of this, certificate pinning has been used in mobile apps, banking apps, payment apps, and other high-security systems.
Be the first to add a comment.