|
|
|
|
|
by NateLawson
5083 days ago
|
|
All of these are good recommendations. Another technology to start preparing for is TACK. It allows you, the server owner, to control browser pinning of your certs while maintaining CA mobility. This gives you the control over your security that Google has over Gmail via Chrome cert pinning without having to issue a new browser build every time you change CAs. One way to think of it is like a domain transfer lock but with cryptography. You control how you unlock your pin to allow mobility to a new CA by sticking a signed file on your SSL server. http://tack.io/ [Disclosure: one of the authors of TACK is a former co-worker.] |
|