|
|
|
|
|
by tedunangst
3442 days ago
|
|
If I screw up max connections or keep alive or some such in nginx.conf I can revert that change with downtime limited to the duration of the bad change. Screw up HPKP with a bad cert roll and you can't just revert. Users will be bifurcated into before and after groups, and you can't fix that without waiting it out. |
|
https://https.cio.gov/certificates/#http-public-key-pinning