Re: intent to unship: HPKP (dynamic key pinning)

2019-11-20 Thread Dana Keeler
preload list, or is it restricted to our own properties? On Sun, Nov 17, 2019, 8:17 PM Dana Keeler <mailto:dkee...@mozilla.com>> wrote: The breadth of the web public key infrastructure (PKI) is both an asset and a risk. Websites have a wide range of certificate authori

intent to unship: HPKP (dynamic key pinning)

2019-11-17 Thread Dana Keeler
The breadth of the web public key infrastructure (PKI) is both an asset and a risk. Websites have a wide range of certificate authorities (CAs) to choose from to obtain certificates for their domains. As a consequence, attackers also have a wide range of potential targets to try to exploit to

Re: try pushes: use a base revision from 2019-02-06 or newer

2019-02-13 Thread Dana Keeler
On 2/12/19 9:15 PM, Randell Jesup wrote: >> if you push to the Try server, use base revisions (= the shared revision on >> top of which you add your changes) from 2019-02-06 or newer, else there >> will be many test failures due to expired certificates. The newer base >> revisions have the fixes