How to fix Http public key pinning issue with a generic codeHow to get .pem file from .key and .crt files?How to create an HTTPS server in Node.js?Node.js HTTPS server ERR_EMPTY_RESPONSECustom SSLSocketFactory not uses a custom trustmanagerPublic key authentication in SafariSSL pinning - setting pinned public keys instead of pinned certificates in AFSecurityPolicyHow to generate HTTPS proxy certificate?Getting NET::ERR_SSL_PINNED_KEY_NOT_IN_CERT_CHAIN error after certificate replacementGCP SSL Certificate Installation Error "The Certificate data is invalid. Please ensure that the private key and public certificate matchHow to fix SSL error when scraping web data using BeautifulSoup

Does Marvel have an equivalent of the Green Lantern?

Change CPU MHz from Registry

Are Finite Automata Turing Complete?

What do you call a weak person's act of taking on bigger opponents?

First-year PhD giving a talk among well-established researchers in the field

How risky is real estate?

Why doesn't a marching band have strings?

What sort of mathematical problems are there in AI that people are working on?

No IMPLICIT_CONVERSION warning in this query plan

Changing the opacity of lines on a plot based on their value

Distance Matrix (plugin) - QGIS

ては's role in this 「追いかけては来ないでしょう」

In the Marvel universe, can a human have a baby with any non-human?

How well known and how commonly used was Huffman coding in 1979?

Can the negators "jamais, rien, personne, plus, ni, aucun" be used in a single sentence?

Is there vegetarian astronaut?

What are the benefits of using the X Card safety tool in comparison to plain communication?

How to perform Login Authentication at the client-side?

What is the legal status of travelling with (unprescribed) methadone in your carry-on?

Change the boot order with no option in UEFI settings

As a DM, how do you control a dysfunctional group wanting different things out of a game?

What happens when your group is victim of a surprise attack but you can't be surprised?

Sho, greek letter

How do I make a very short story impactful?



How to fix Http public key pinning issue with a generic code


How to get .pem file from .key and .crt files?How to create an HTTPS server in Node.js?Node.js HTTPS server ERR_EMPTY_RESPONSECustom SSLSocketFactory not uses a custom trustmanagerPublic key authentication in SafariSSL pinning - setting pinned public keys instead of pinned certificates in AFSecurityPolicyHow to generate HTTPS proxy certificate?Getting NET::ERR_SSL_PINNED_KEY_NOT_IN_CERT_CHAIN error after certificate replacementGCP SSL Certificate Installation Error "The Certificate data is invalid. Please ensure that the private key and public certificate matchHow to fix SSL error when scraping web data using BeautifulSoup






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty margin-bottom:0;








0















I've added below section in my httpd conf file to support public key pinning for my website:



Header set Public-Key-Pins "pinsha256="my_public_keyhash_generatedfrom_mycertificate.crt"; max-age=31536000; includeSubDomains"


Tomorrow if I change my certificate , I've to hard code the new public key here, how can I use a generic code snippet for Http public key pinning for various domain and various environment.










share|improve this question






















  • What is a generic code snippet in that context? By definition, each time you change your key (not necessarily each time you change your certificate, you can renew certificates using same key) you will need to change your header. Note that for multiple reasons, browsers are not in love anymore with HPKP so you might need to assess if you really need to use it or not.

    – Patrick Mevzek
    Mar 25 at 16:11











  • Thanks for this update. So each time if I'm changing the certificate I've to update the public hash accordingly and there's no way around to this.

    – Saurabh Kumar
    Mar 26 at 11:51











  • That is not true: again, you can renew a certificate without changing the public key it is based on. See --reuse-key option in certbot for example.

    – Patrick Mevzek
    Mar 26 at 14:59

















0















I've added below section in my httpd conf file to support public key pinning for my website:



Header set Public-Key-Pins "pinsha256="my_public_keyhash_generatedfrom_mycertificate.crt"; max-age=31536000; includeSubDomains"


Tomorrow if I change my certificate , I've to hard code the new public key here, how can I use a generic code snippet for Http public key pinning for various domain and various environment.










share|improve this question






















  • What is a generic code snippet in that context? By definition, each time you change your key (not necessarily each time you change your certificate, you can renew certificates using same key) you will need to change your header. Note that for multiple reasons, browsers are not in love anymore with HPKP so you might need to assess if you really need to use it or not.

    – Patrick Mevzek
    Mar 25 at 16:11











  • Thanks for this update. So each time if I'm changing the certificate I've to update the public hash accordingly and there's no way around to this.

    – Saurabh Kumar
    Mar 26 at 11:51











  • That is not true: again, you can renew a certificate without changing the public key it is based on. See --reuse-key option in certbot for example.

    – Patrick Mevzek
    Mar 26 at 14:59













0












0








0








I've added below section in my httpd conf file to support public key pinning for my website:



Header set Public-Key-Pins "pinsha256="my_public_keyhash_generatedfrom_mycertificate.crt"; max-age=31536000; includeSubDomains"


Tomorrow if I change my certificate , I've to hard code the new public key here, how can I use a generic code snippet for Http public key pinning for various domain and various environment.










share|improve this question














I've added below section in my httpd conf file to support public key pinning for my website:



Header set Public-Key-Pins "pinsha256="my_public_keyhash_generatedfrom_mycertificate.crt"; max-age=31536000; includeSubDomains"


Tomorrow if I change my certificate , I've to hard code the new public key here, how can I use a generic code snippet for Http public key pinning for various domain and various environment.







ssl https websecurity






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Mar 25 at 10:21









Saurabh KumarSaurabh Kumar

145 bronze badges




145 bronze badges












  • What is a generic code snippet in that context? By definition, each time you change your key (not necessarily each time you change your certificate, you can renew certificates using same key) you will need to change your header. Note that for multiple reasons, browsers are not in love anymore with HPKP so you might need to assess if you really need to use it or not.

    – Patrick Mevzek
    Mar 25 at 16:11











  • Thanks for this update. So each time if I'm changing the certificate I've to update the public hash accordingly and there's no way around to this.

    – Saurabh Kumar
    Mar 26 at 11:51











  • That is not true: again, you can renew a certificate without changing the public key it is based on. See --reuse-key option in certbot for example.

    – Patrick Mevzek
    Mar 26 at 14:59

















  • What is a generic code snippet in that context? By definition, each time you change your key (not necessarily each time you change your certificate, you can renew certificates using same key) you will need to change your header. Note that for multiple reasons, browsers are not in love anymore with HPKP so you might need to assess if you really need to use it or not.

    – Patrick Mevzek
    Mar 25 at 16:11











  • Thanks for this update. So each time if I'm changing the certificate I've to update the public hash accordingly and there's no way around to this.

    – Saurabh Kumar
    Mar 26 at 11:51











  • That is not true: again, you can renew a certificate without changing the public key it is based on. See --reuse-key option in certbot for example.

    – Patrick Mevzek
    Mar 26 at 14:59
















What is a generic code snippet in that context? By definition, each time you change your key (not necessarily each time you change your certificate, you can renew certificates using same key) you will need to change your header. Note that for multiple reasons, browsers are not in love anymore with HPKP so you might need to assess if you really need to use it or not.

– Patrick Mevzek
Mar 25 at 16:11





What is a generic code snippet in that context? By definition, each time you change your key (not necessarily each time you change your certificate, you can renew certificates using same key) you will need to change your header. Note that for multiple reasons, browsers are not in love anymore with HPKP so you might need to assess if you really need to use it or not.

– Patrick Mevzek
Mar 25 at 16:11













Thanks for this update. So each time if I'm changing the certificate I've to update the public hash accordingly and there's no way around to this.

– Saurabh Kumar
Mar 26 at 11:51





Thanks for this update. So each time if I'm changing the certificate I've to update the public hash accordingly and there's no way around to this.

– Saurabh Kumar
Mar 26 at 11:51













That is not true: again, you can renew a certificate without changing the public key it is based on. See --reuse-key option in certbot for example.

– Patrick Mevzek
Mar 26 at 14:59





That is not true: again, you can renew a certificate without changing the public key it is based on. See --reuse-key option in certbot for example.

– Patrick Mevzek
Mar 26 at 14:59












0






active

oldest

votes














Your Answer






StackExchange.ifUsing("editor", function ()
StackExchange.using("externalEditor", function ()
StackExchange.using("snippets", function ()
StackExchange.snippets.init();
);
);
, "code-snippets");

StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "1"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);













draft saved

draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55335609%2fhow-to-fix-http-public-key-pinning-issue-with-a-generic-code%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes















draft saved

draft discarded
















































Thanks for contributing an answer to Stack Overflow!


  • Please be sure to answer the question. Provide details and share your research!

But avoid


  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.

To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55335609%2fhow-to-fix-http-public-key-pinning-issue-with-a-generic-code%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Kamusi Yaliyomo Aina za kamusi | Muundo wa kamusi | Faida za kamusi | Dhima ya picha katika kamusi | Marejeo | Tazama pia | Viungo vya nje | UrambazajiKuhusu kamusiGo-SwahiliWiki-KamusiKamusi ya Kiswahili na Kiingerezakuihariri na kuongeza habari

Swift 4 - func physicsWorld not invoked on collision? The Next CEO of Stack OverflowHow to call Objective-C code from Swift#ifdef replacement in the Swift language@selector() in Swift?#pragma mark in Swift?Swift for loop: for index, element in array?dispatch_after - GCD in Swift?Swift Beta performance: sorting arraysSplit a String into an array in Swift?The use of Swift 3 @objc inference in Swift 4 mode is deprecated?How to optimize UITableViewCell, because my UITableView lags

Access current req object everywhere in Node.js ExpressWhy are global variables considered bad practice? (node.js)Using req & res across functionsHow do I get the path to the current script with Node.js?What is Node.js' Connect, Express and “middleware”?Node.js w/ express error handling in callbackHow to access the GET parameters after “?” in Express?Modify Node.js req object parametersAccess “app” variable inside of ExpressJS/ConnectJS middleware?Node.js Express app - request objectAngular Http Module considered middleware?Session variables in ExpressJSAdd properties to the req object in expressjs with Typescript