|
|
|
|
|
by bdonlan
3354 days ago
|
|
With HKPK (which I think you're talking about here - HSTS just requires that https be used at all) expiration is not an issue as you whitelist the key, not the certificate (and are required to list a backup key, which should ideally be offline). By listing the server's own key, possibly in addition to a trusted CA, you ensure that in the worst case you can renew using the same key. Obviously when you're first rolling it out you should use a short duration to allow for a quick rollback if something goes wrong. Of course nothing about this truly prevents someone who didn't take proper precautions when setting it up from screwing it up. Unfortunately it's hard to make a more tolerant system without also making it vulnerable again... |
|
Not HKPK.