3 ms·
It is part of the RFC: if a certificate is signed by a root certificate that is trusted in your private store (meaning it was added later on), HPKP is ignored.
by jusob 10y ago
It is part of the RFC: if a certificate is signed by a root certificate that is trusted in your private store (meaning it was added later on), HPKP is ignored. Unfortunately, this is required in the enterprise world where corporate MiTM is often done (Palo Alto Network SSL proxy, Websense/Forcepoint, Zscaler, Blue Coat, etc.) for content inspection.
- voidlogic 10y ago>Unfortunately, this is required in the enterprise world where corporate MiTM is often done This still should not be the default, rather corps should have an easy about:config switch they can flip. The default should protect private users.
- ryan-c 10y agoHow is that a meaningfully different experience? Anything able to install a CA can flip the config value.