W3C home > Mailing lists > Public > public-webappsec@w3.org > January 2015

Re: Proposal: A pinning mechanism for CSP?

From: Chris Palmer <palmer@google.com>
Date: Fri, 23 Jan 2015 10:42:29 -0800
Message-ID: <CAOuvq21tQs8b8pOHmZxkh5LZCmaxNbBRa-BQriT_0SYSFX=Umw@mail.gmail.com>
To: Mike West <mkwst@google.com>
Cc: Jim Manico <jim.manico@owasp.org>, Frederik Braun <fbraun@mozilla.com>, "public-webappsec@w3.org" <public-webappsec@w3.org>, yan zhu <yan@mit.edu>, Ryan Sleevi <sleevi@google.com>, Brad Hill <hillbrad@gmail.com>, Dan Veditz <dveditz@mozilla.com>
On Fri, Jan 23, 2015 at 9:43 AM, Mike West <mkwst@google.com> wrote:

> Actually, there might be some subtlety here (can't HSTS/PKP turn itself off
> with a 0 max-age? Chris? Ryan? I didn't see that logic in a quick skim of
> the RFCs)

Yes, both HPKP and HSTS treat max=age=0 as "turn it off".

http://tools.ietf.org/html/rfc6797#section-6.1.1
Received on Friday, 23 January 2015 18:42:57 UTC

This archive was generated by hypermail 2.3.1 : Monday, 23 October 2017 14:54:09 UTC