{"id":"redis-pin-root-ca-not-intermediate-leaf","text":"Azure Cache for Redis certificate pinning should target root CAs (Baltimore CyberTrust Root, Microsoft RSA Root 2017, DigiCert Global Root G2), never intermediate or leaf certificates.","truth_value":"IN","source":"entries/2026/03/10/redis-best-practices.md","source_url":"","source_hash":"a047d725bfd7ac64","justifications":[],"dependents":[],"metadata":{},"explanation":{"steps":[{"node":"redis-pin-root-ca-not-intermediate-leaf","truth_value":"IN","reason":"premise"}]}}