Menu

#1985 FTPS certificate fingerprint ignored

KeePass_2.x
closed
nobody
None
5
2020-09-06
2020-08-20
Lars
No

I am using Keepass 2.45 with plugin ioprotocolext 1.16.0.0 to get the password database from a ftps server.

I am trying to improve security by providing the SSL certificate fingerprint in the settings of the Open URL dialog.
But whatever fingerprint I am adding it does not complain when opening the file from the server. I would have expected, that opening is rejected or at least a warning is shown in case the fingerprint does not match.

Am I doing/expecting something wrong, or is this a bug?

Discussion

  • Paul

    Paul - 2020-08-21

    KeePass accepts the crertificate as long as it's valid (you can tell it to accept an invalid one too). It's about encryption of the comms, not authentication.

    cheers, Paul

     
  • Dominik Reichl

    Dominik Reichl - 2020-09-06
    • status: open --> closed
     
  • Dominik Reichl

    Dominik Reichl - 2020-09-06

    I've tested this now. For FTPS, WinSCP seems to ignore the specified certificate fingerprint if the server's certificate is valid. The specified certificate fingerprint is used only to accept an invalid certificate.

    I haven't found any way to enforce a certificate fingerprint comparison for a valid certificate. Maybe this gets added in a future WinSCP version; feel free to post a feature request on the WinSCP website (if it doesn't exist yet).

    Thanks and best regards,
    Dominik

     

Log in to post a comment.