← Back to Labs

Certificate Pinning Outcome Explorer

Compare plain PKI, brittle certificate pins, SPKI pins, and backup-pin rotations under the same TLS scenarios.

Pin strategyChoose what the client enforces after path validation
Pinned primary SPKI
sha256/8A1euX3N7sLQW0fE4y0QxQ8Fm7g1bVn0m3fV2H1x6Eg=
Pinned backup SPKI
sha256/wY3R9W1vL6x4pQF5dD4nS5qP2tXg8rM4aC1uZ7bK0LA=
Presented chainReal edge certificateissuer: DigiCert TLS RSA SHA256 2020 CA1leaf fp: 19:44:62:8A:4D:7C:91:AASPKI: sha256/8A1euX3N7sLQW0fE4y0QxQ...Client trust rulesSPKI pinroot: Trusted public rootpath validation: passpin rule: Match the expected public key hash.Connection resultACCEPTleaf pin: matchprimary SPKI: matchbackup SPKI: missSPKIPinning does not replace PKI. It narrows the already-accepted result.
Scenario
Real edge certificate
No interception. Expected chain and expected key.
Operational reading
Accept: the chain validates and the chosen pin rule matches.
Step 1 / 5Normal PKI accepts the real service certificate

The first connection succeeds because the certificate chains to a trusted root and the key matches what the app expected during rollout.

Arrow keys to navigate · R to reset

Tap dots to jump to any step

Read the full article →Take the quiz →