aboutsummaryrefslogtreecommitdiffstats
path: root/OpenKeychain/src/main/java/org/sufficientlysecure/keychain/KeychainApplication.java
diff options
context:
space:
mode:
authorVincent Breitmoser <valodim@mugenguild.com>2015-09-21 14:41:32 +0200
committerVincent Breitmoser <valodim@mugenguild.com>2015-09-21 14:41:32 +0200
commit624299b3f14512fef1ade9e19ebe44b9a7906775 (patch)
tree6c0224f7eb3a0d7648618d316fff8d87c5753031 /OpenKeychain/src/main/java/org/sufficientlysecure/keychain/KeychainApplication.java
parent2b83ed6cfc08c32483b42a47c1962d44f8c5b434 (diff)
parent7d9e44afd7f15b4a7db442a430cb6f570ac2a510 (diff)
downloadopen-keychain-624299b3f14512fef1ade9e19ebe44b9a7906775.tar.gz
open-keychain-624299b3f14512fef1ade9e19ebe44b9a7906775.tar.bz2
open-keychain-624299b3f14512fef1ade9e19ebe44b9a7906775.zip
Merge branch 'master' of github.com:open-keychain/open-keychain
Diffstat (limited to 'OpenKeychain/src/main/java/org/sufficientlysecure/keychain/KeychainApplication.java')
-rw-r--r--OpenKeychain/src/main/java/org/sufficientlysecure/keychain/KeychainApplication.java6
1 files changed, 6 insertions, 0 deletions
diff --git a/OpenKeychain/src/main/java/org/sufficientlysecure/keychain/KeychainApplication.java b/OpenKeychain/src/main/java/org/sufficientlysecure/keychain/KeychainApplication.java
index 45d81749a..56dd9a4cb 100644
--- a/OpenKeychain/src/main/java/org/sufficientlysecure/keychain/KeychainApplication.java
+++ b/OpenKeychain/src/main/java/org/sufficientlysecure/keychain/KeychainApplication.java
@@ -100,6 +100,12 @@ public class KeychainApplication extends Application {
TlsHelper.addPinnedCertificate("hkps.pool.sks-keyservers.net", getAssets(), "hkps.pool.sks-keyservers.net.CA.cer");
TlsHelper.addPinnedCertificate("pgp.mit.edu", getAssets(), "pgp.mit.edu.cer");
+ // NOTE:
+ // keybase.io.CA.cer only holds the CA issuing the actual keybase.io certificate, but this
+ // is better than no pinning!
+ // We are not using https://github.com/keybase/node-client/blob/master/src/ca.iced
+ // because it is only valid for api.keybase.io (https://github.com/keybase/keybase-issues/issues/964)
+ TlsHelper.addPinnedCertificate("keybase.io", getAssets(), "keybase.io.CA.cer");
TemporaryStorageProvider.cleanUp(this);