Definition · TLS & Certificates
What is Certificate Pinning?
Normal TLS validation accepts any certificate signed by any CA in the client’s trust store. That is a broad grant of authority: hundreds of organisations can technically issue a certificate for your domain. Certificate pinning narrows it. The client is configured in advance with the certificate, or more usually the public key, it expects from a particular host, and rejects the connection if what it sees does not match — even when the presented certificate is otherwise perfectly valid.
Pinning is usually done on the public key rather than the whole certificate, so renewal with the same key pair does not break the pin. Pinning an intermediate CA is a middle ground: it survives reissuance but still narrows trust to one issuer.
Where it is used, and where it was withdrawn
Pinning is standard practice in mobile applications and in machine-to-machine clients, where the developer controls both ends and can ship a new pin with an application update. Native platform APIs and Android’s network security configuration make it straightforward to declare.
The browser equivalent, HTTP Public Key Pinning (HPKP), was deprecated and removed. It let a site send pins in a header that browsers then enforced for a set period, which created two serious problems: a site that lost its pinned keys made itself unreachable until the pin expired, and an attacker who briefly controlled a site could set long-lived hostile pins to deny service afterwards. Browsers dropped support, and CT-log monitoring plus CAA records became the recommended alternative for detecting and preventing mis-issuance.
Trade-offs to weigh
- Operational fragility. A pin is a hard dependency on a key you must never lose. Always ship a backup pin for a key held offline.
- Renewal coupling. Pinning interacts badly with short certificate lifetimes and automated ACME issuance unless the key is retained across renewals.
- Update latency. Clients that cannot be updated quickly should not carry aggressive pins.
- It also blocks inspection proxies, which is sometimes the point and sometimes an unwelcome surprise for enterprise customers.
Related concepts
See certificate authority, certificate chain, certificate revocation, Certificate Transparency logs and defence in depth.