Menu

#123 Query on Certificate Pinning in v3.0

v1.0 (example)
open
nobody
5
2021-02-23
2021-02-23
No

Hi,
A query about Embedded SSL/TLS certificates and certificate pinning.
I am aware that this is not supported in SEB Win v3.0 but I was wondering what was the likelihood that you would add it to v3.0 considering the trend with current browsers has been to remove certificate pinning.
Would it drop off SEB Mac eventually too?
Thanks

Discussion

  • Daniel Schneider

    Hi,

    We would definitely like to keep the certificate pinning feature/bring it back to SEB 3.x. I think it is in our roadmap, but it didn't had the highest priority when we refactored SEB 2 -> 3 and currently there some other highly demanded, important features which we have to prioritize over the certificate embedding/pinning.

    There are definitely no plans to remove it from the Mac and iOS versions, BUT I have to transition to the "modern" WebKit 2 WKWebView (started working on it just now) and for a while I wasn't sure if it really is possible to implement certificate pinning there (WKWebView is still limited in some areas compared to the classic WebView). Some internet research shows that it should still be possible, so it's very likely it will stay.

    I'm actually happy to hear that someone is using it, as we didn't get much feedback about it since we added support for it.

    Cheers,
    Daniel

     

    Last edit: Daniel Schneider 2021-02-23
  • Neal Varghese

    Neal Varghese - 2021-02-23

    @danschlet - Thanks for the prompt reply. Actually we were considering whether to start using it or not in v2.4, or not bother at all if there is no migration path to v3.0. We also have concerns about the value of using pinning with an opensource product on BYOD devices.

     
MongoDB Logo MongoDB