3 ms·
HPKP is HTTP Public Key Pinning, you aren't pinning certificates, you're pinning the public key. This means that you don't necessarily need to change any pins w
by Scott_Helme_ 11y ago
HPKP is HTTP Public Key Pinning, you aren't pinning certificates, you're pinning the public key. This means that you don't necessarily need to change any pins when you renew certificates as the certificate can use the same key pair. The only time you need to consume a backup pin when renewing the certificate is if you have a new public key signed. I think it's important to understand the difference before you try to deploy HPKP.
As for pinning the CA instead of your own public key, you can see my other comments in this thread with links about how GitHub pin their CA and a backup CA. I also have a link with information on the various levels in a chain you can pin at like the leaf, intermediate and root. Each has its own benefits and drawbacks.
- cmrx64 11y agoI see, I hadn't made that obvious connection -- it's right in the name! (been awake for ~28 hours) That's much nicer. This is the first I've seen that header, it's good to know it exists -- I've implemented it in other ad-hoc protocols.