3 ms·
> ¹ This is assuming browsers won't accept HPKP headers that don't pass for the current connection. I haven't actually checked this. RFC 7469 requires this (h
by TimWolla 11y ago
> ¹ This is assuming browsers won't accept HPKP headers that don't pass for the current connection. I haven't actually checked this.
RFC 7469 requires this (https://tools.ietf.org/html/rfc7469#section-2.5 https://tools.ietf.org/html/rfc7469#section-2.5):
o The TLS connection was authenticated with a certificate chain
containing at least one of the SPKI structures indicated by at
least one of the given SPKI Fingerprints (see Section 2.6).
- deleted 11y ago[deleted]