-
@aprilmpls @jvehent Sure. But you can’t garanty your visitors are fresh enough to support a change of key. You have to wait at least max-age
-
@aprilmpls @jvehent between last planned change in case of (unplanned) compromission.
-
@aprilmpls @jvehent (Or more generally, N max-age if you publish N backup keys on your HPKP, assuming all backups are safe)
-
@aprilmpls @jvehent Best/worst example is @letsencrypt. With default config (key renew each 90d), If you set HPKP to 60d and you are […]
-
@aprilmpls @jvehent @letsencrypt compromised between 0 to 60 days after a key renew you CAN’T change your key without breaking some visitors
-
@aprilmpls @jvehent @letsencrypt (The example is in practice worst because you can’t guess your future key so no backup possible […]
-
@aprilmpls @jvehent and so default @letsencrypt configuration is incompatible with HPKP)
aeris22’s Twitter Archive—№ 38,664