<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Trust Management on Nalar</title>
    <link>https://nalar.dev/tags/trust-management/</link>
    <description>Recent content in Trust Management on Nalar</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 09 Sep 2026 00:00:00 +0700</lastBuildDate>
    <atom:link href="https://nalar.dev/tags/trust-management/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Treat Certificate Pinning as a High-Cost Trust Decision</title>
      <link>https://nalar.dev/treat-certificate-pinning-as-a-high-cost-trust-decision/</link>
      <pubDate>Wed, 09 Sep 2026 00:00:00 +0700</pubDate>
      <guid>https://nalar.dev/treat-certificate-pinning-as-a-high-cost-trust-decision/</guid>
      <description>&lt;p&gt;TLS normally lets a client authenticate a server through a certificate chain anchored in a trusted certificate authority. A developer may look at that broad trust model and decide to add certificate pinning: require the server to present not only a normally valid certificate, but also certificate or public-key material that the application already expects.&lt;/p&gt;&#xA;&lt;p&gt;That extra restriction can reduce risk in a narrow threat model. It can also turn an ordinary certificate or key rotation into an outage if the application has no usable replacement pin. For many applications, especially ordinary websites, the operational risk is not justified.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
