Hacker News new | ask | show | jobs
by gchambert 1641 days ago
It's not 100% related but certificate pinning (HKPK) is only enforced for CA trusted by browser. It is ignored if the leaf certificate is signed by a user-imported CA (or deployed by enterprise policies). Maybe the same applies for SCT?