Open jbicha opened 7 years ago
Since you already support checking for HPKP, how about OCSP must-staple?
https://blog.mozilla.org/security/2015/11/23/improving-revocation-ocsp-must-staple-and-short-lived-certificates/
+1.
+1
Since you already support checking for HPKP, how about OCSP must-staple?
https://blog.mozilla.org/security/2015/11/23/improving-revocation-ocsp-must-staple-and-short-lived-certificates/