Hacker News new | ask | show | jobs
by prolurker 3195 days ago
Correct, but, even if not explicitly said, the cached entries should be associated to the certificate's fingerprint and immediately discarded once the certificate expires or is changed.
1 comments

Certificates often change for legitimate reasons, e.g. Let's Encrypt certificates which must be changed every 3 months.
That would be ok.