Hacker News new | ask | show | jobs
by mhils 702 days ago
There's OCSP Must-Staple, which makes MITM without stapling impossible. That is, if the client implements it and does not fail open. :)