FTPS certificate fingerprint ignored
A lightweight and easy-to-use password manager
Brought to you by:
dreichl
I am using Keepass 2.45 with plugin ioprotocolext 1.16.0.0 to get the password database from a ftps server.
I am trying to improve security by providing the SSL certificate fingerprint in the settings of the Open URL dialog.
But whatever fingerprint I am adding it does not complain when opening the file from the server. I would have expected, that opening is rejected or at least a warning is shown in case the fingerprint does not match.
Am I doing/expecting something wrong, or is this a bug?
KeePass accepts the crertificate as long as it's valid (you can tell it to accept an invalid one too). It's about encryption of the comms, not authentication.
cheers, Paul
I've tested this now. For FTPS, WinSCP seems to ignore the specified certificate fingerprint if the server's certificate is valid. The specified certificate fingerprint is used only to accept an invalid certificate.
I haven't found any way to enforce a certificate fingerprint comparison for a valid certificate. Maybe this gets added in a future WinSCP version; feel free to post a feature request on the WinSCP website (if it doesn't exist yet).
Thanks and best regards,
Dominik