Enforce optional Android JMAP SPKI pins #19
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/android-spki-pinning"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Adds optional Android JMAP SPKI pin enforcement using typed Jerboa code.
The saved HTTPS server URL may include a
#sha256/<base64>pin fragment. The fragment is preserved when resolving JMAP endpoints, never sent in HTTP requests, and the first peer certificate's public-key digest is checked before response parsing. Mismatches raise an explicit TLS verification failure.Validation:
make -C android apk(BUILD SUCCESSFUL)jerboa_check_balancepassed for app.ss, jmap-client.ss, and tls-pin.ss428a24d74e78fd59ee2e