2011-03-30 13:49:47 +00:00
|
|
|
.TH THUMBPRINT 6
|
|
|
|
.SH NAME
|
|
|
|
thumbprint \- public key thumbprints
|
|
|
|
.SH DESCRIPTION
|
|
|
|
.PP
|
|
|
|
Applications in Plan 9 that use public keys for authentication,
|
|
|
|
for example by calling
|
|
|
|
.B tlsClient
|
|
|
|
and
|
|
|
|
.B okThumbprint
|
2017-04-23 17:00:08 +00:00
|
|
|
or
|
|
|
|
.B okCertificate
|
2011-03-30 13:49:47 +00:00
|
|
|
(see
|
|
|
|
.IR pushtls (2)),
|
|
|
|
check the remote side's public key by comparing against
|
|
|
|
thumbprints from a trusted list.
|
|
|
|
The list is maintained by people who set local policies
|
|
|
|
about which servers can be trusted for which applications,
|
|
|
|
thereby playing the role taken by certificate authorities
|
|
|
|
in PKI-based systems.
|
|
|
|
By convention, these lists are stored as files in
|
|
|
|
.B /sys/lib/tls/
|
|
|
|
and protected by normal file system permissions.
|
|
|
|
.PP
|
|
|
|
Such a thumbprint file comprises lines made up of
|
|
|
|
attribute/value pairs of the form
|
|
|
|
.IB attr = value
|
|
|
|
or
|
|
|
|
.IR attr .
|
2017-04-23 17:00:08 +00:00
|
|
|
The first attribute must be the application tag:
|
2011-03-30 13:49:47 +00:00
|
|
|
.B x509
|
2017-04-23 17:00:08 +00:00
|
|
|
for tls applications or
|
|
|
|
.B ssh
|
|
|
|
for ssh server fingerprints.
|
|
|
|
The second attribute must be a hash type of
|
|
|
|
.B sha1=
|
|
|
|
or
|
|
|
|
.BI sha256=
|
|
|
|
followed by the hex or base64 encoded hash of binary certificate
|
|
|
|
or public key.
|
2011-03-30 13:49:47 +00:00
|
|
|
All other attributes are treated as comments.
|
|
|
|
The file may also contain lines of the form
|
2017-04-23 17:00:08 +00:00
|
|
|
.B #include
|
|
|
|
.I file
|
2011-03-30 13:49:47 +00:00
|
|
|
.PP
|
|
|
|
For example, a web server might have thumbprint
|
|
|
|
.EX
|
|
|
|
x509 sha1=8fe472d31b360a8303cd29f92bd734813cbd923c cn=*.cs.bell-labs.com
|
|
|
|
.EE
|
|
|
|
.SH "SEE ALSO"
|
|
|
|
.IR pushtls (2)
|