Certificate Pinning
Noun · Security & Infosec
Definitions
Certificate Pinning is a trust strategy that restricts which certificate or public key a client will accept for a service. Security teams use it to enforce trust, reduce exposure, improve detection, or standardize secure operations in production environments. Its value depends on correct configuration, lifecycle management, and surrounding controls, because weak defaults, poor integration, or missing visibility can create gaps that attackers exploit.
In plain English: Certificate Pinning is a security concept or control that helps organizations protect systems, manage trust, and notice suspicious behavior before damage spreads.
Example: "After the review, the security team rolled out Certificate Pinning in the affected environment, documented the operating procedure, and verified through logs and test cases that the control reduced exposure without breaking normal administrative or user workflows."
Related Terms
- Certificate Authority
- Certificate
- Certificate Transparency
- Attestation
- DANE
- Hardware Root of Trust
- Let's Encrypt
- Mutual TLS
- OCSP
- OCSP Stapling
- Root Certificate
- Certificate Chain
- Certificate Lifecycle
- Chain of Trust
- Client Certificate
- Heart Bleed
- High Assurance
- Identity Proofing
- Multi-Domain Certificate
- Offline Root CA
- Public Certificate