stubby: add SPKI pin set for Cloudflare cert
authorTony Ambardar <redacted>
Tue, 7 Aug 2018 10:11:19 +0000 (03:11 -0700)
committerguidosarducci <redacted>
Mon, 24 Sep 2018 04:55:03 +0000 (21:55 -0700)
commit1170686cbab9a017d49cb532918a4e4c4a9c490d
treea4d3acc559682a8bee42dd536610e3c988f37c45
parent8b2de594de0219681ba9630b8390738a1afb7e4e
stubby: add SPKI pin set for Cloudflare cert

Add an SPKI pin for Cloudflare to help prevent MITM and downgrade attacks,
as described in RFC7858 (DNS over TLS). The setup of SPKI and the specific
SHA256 certificate hash are taken from Cloudflare's DoT configuration guide
published at https://developers.cloudflare.com/1.1.1.1/dns-over-tls/.

Note that the certificate is valid to March 25th 2020, 13:00 CET, which
provides ample time for issuance of a backup pin to support future key
rollover.

Signed-off-by: Tony Ambardar <redacted>
net/stubby/files/stubby.yml
git clone https://git.99rst.org/PROJECT