Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> But also: you can pin to a specific certificate, not just a CA.

I think the general best practices for pinning are to pin a CA or two, and a backup key; in case your keys get compromised, you can reissue with your preferred CA; in case your CA gets delisted, you can get a cert issued with your backup key from a still trusted CA. You could have a series of keys and trust those, but it seems like that would be an easy way for you to shoot yourself in the foot.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: