During that time, user-agents will require that the host presents a Certificate Chain including at least one Subject Public Key Info structure whose Certificate Fingerprint matches one of the pinned Certificate Fingerprint for that host. By effectively reducing the number of trusted authorities who can authenticate the domain during the lifetime of the pin, pinning may reduce the incidence of Man-In-The-Middle attacks due to compromised Certification Authorities.
Public Key Pinning Extension for HTTP is a form of Certificate Pinning
- based on information obtained 2017-10-30-
- based on information obtained 2017-10-30-