Re: [squid-users] SSL-bump and Public Key Piinning (HPKP)

2015-07-05 Thread Jason Haar
On 6/07/15 2:01 am, Walter H. wrote: reply_header_access Public-Key-Pins deny all but this doesn't really work; is there another way? If you think you can override all pinning options, then I'm afraid you're mistaken. Well written security apps should do their darndest to stop TLS intercept fr

[squid-users] SSL-bump and Public Key Piinning (HPKP)

2015-07-05 Thread Walter H.
Hello, I'm using squid with ssl-bump, after updating (I update only in bigger steps and not this often) my browser I realize, that this supports HPKP; I didn't find how to deactivate this - Chrome 43 so I thought, I could prevent squid of replying this header field with this: reply_header_acc