3 ms·
A lot of advice online, including my own, recommends that once you start enforcing a policy you keep the max-age quite short for a period of time. The report-on
by Scott_Helme_ 11y ago
A lot of advice online, including my own, recommends that once you start enforcing a policy you keep the max-age quite short for a period of time. The report-only mode is helpful in identifying issues but given the nature of what HPKP is and does, jumping straight to a high max-age value when you start enforcing the policy isn't wise.
- huhtenberg 11y agoThey don't use reporting.
- Scott_Helme_ 11y agoNo, but that doesn't impact the operation of enforcing the use of their public keys which is the main purpose. It's definitely preferable to have reporting though.
- ptoomey3 11y agoWhen we first deployed our policy there was no support for reporting in browsers. I think that Firefox still lacks support and chrome only added support recently (I'd have to double check, or I'm sure Scott knows).
- Scott_Helme_ 11y agoExactly right. The only browser that will send HPKP reports right now is Chrome and that was very recent.
- ptoomey3 11y agoYeah, we deployed this short max-age just to be safe on the initial deployment. I have a pull request open right now to switch our backup CA and add the intermediate certificate pins (to avoid possible future cross-signing issues) before we start bumping max-age. HPKP requires careful planning and a low max-age is definitely the way to go until you are 100% confident in your policy.