Re: Proposal: A pinning mechanism for CSP?

On Fri, Jan 23, 2015 at 9:43 AM, Mike West <mkwst@google.com> wrote:

> Actually, there might be some subtlety here (can't HSTS/PKP turn itself off
> with a 0 max-age? Chris? Ryan? I didn't see that logic in a quick skim of
> the RFCs)

Yes, both HPKP and HSTS treat max=age=0 as "turn it off".

http://tools.ietf.org/html/rfc6797#section-6.1.1

Received on Friday, 23 January 2015 18:42:57 UTC