Validating x509 certificates

25 Feb

Once a certificate or public key is known or seen for a host, the certificate or public key is associated or 'pinned' to the host.

It explains what exactly "keytool -genkeypair" does clearly: "Generates a key pair (a public key and associated private key).As with a certificate, the program checks the extracted public key with its embedded copy of the public key. First, it's harder to work with keys (versus certificates) since you must extract the key from the certificate. Net, buts it's uncomfortable in Cocoa/Cocoa Touch and Open SSL.Second, the key is static and may violate key rotation policies.Downloading/unpacking requests Cannot fetch index base URL Could not find any downloads that satisfy the requirement requests Cleaning up...No distributions at all found for Downloading/unpacking requests Getting page Could not fetch URL connection error: [Errno 1] _ssl.c:504: error:14090086: SSL routines: SSL3_GET_SERVER_CERTIFICATE:certificate verify failed Will skip URL when looking for download links for requests alternate CA bundle needed to include the Digi Cert “High Assurance EV Root CA” and “High Assurance CA-3” certificates, both of which can be obtained from the Digi Cert Root Certificates page.