How to fix Http public key pinning issue with a generic codeHow to get .pem file from .key and .crt files?How to create an HTTPS server in Node.js?Node.js HTTPS server ERR_EMPTY_RESPONSECustom SSLSocketFactory not uses a custom trustmanagerPublic key authentication in SafariSSL pinning - setting pinned public keys instead of pinned certificates in AFSecurityPolicyHow to generate HTTPS proxy certificate?Getting NET::ERR_SSL_PINNED_KEY_NOT_IN_CERT_CHAIN error after certificate replacementGCP SSL Certificate Installation Error "The Certificate data is invalid. Please ensure that the private key and public certificate matchHow to fix SSL error when scraping web data using BeautifulSoup
Does Marvel have an equivalent of the Green Lantern?
Change CPU MHz from Registry
Are Finite Automata Turing Complete?
What do you call a weak person's act of taking on bigger opponents?
First-year PhD giving a talk among well-established researchers in the field
How risky is real estate?
Why doesn't a marching band have strings?
What sort of mathematical problems are there in AI that people are working on?
No IMPLICIT_CONVERSION warning in this query plan
Changing the opacity of lines on a plot based on their value
Distance Matrix (plugin) - QGIS
ては's role in this 「追いかけては来ないでしょう」
In the Marvel universe, can a human have a baby with any non-human?
How well known and how commonly used was Huffman coding in 1979?
Can the negators "jamais, rien, personne, plus, ni, aucun" be used in a single sentence?
Is there vegetarian astronaut?
What are the benefits of using the X Card safety tool in comparison to plain communication?
How to perform Login Authentication at the client-side?
What is the legal status of travelling with (unprescribed) methadone in your carry-on?
Change the boot order with no option in UEFI settings
As a DM, how do you control a dysfunctional group wanting different things out of a game?
What happens when your group is victim of a surprise attack but you can't be surprised?
Sho, greek letter
How do I make a very short story impactful?
How to fix Http public key pinning issue with a generic code
How to get .pem file from .key and .crt files?How to create an HTTPS server in Node.js?Node.js HTTPS server ERR_EMPTY_RESPONSECustom SSLSocketFactory not uses a custom trustmanagerPublic key authentication in SafariSSL pinning - setting pinned public keys instead of pinned certificates in AFSecurityPolicyHow to generate HTTPS proxy certificate?Getting NET::ERR_SSL_PINNED_KEY_NOT_IN_CERT_CHAIN error after certificate replacementGCP SSL Certificate Installation Error "The Certificate data is invalid. Please ensure that the private key and public certificate matchHow to fix SSL error when scraping web data using BeautifulSoup
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty margin-bottom:0;
I've added below section in my httpd conf file to support public key pinning for my website:
Header set Public-Key-Pins "pinsha256="my_public_keyhash_generatedfrom_mycertificate.crt"; max-age=31536000; includeSubDomains"
Tomorrow if I change my certificate , I've to hard code the new public key here, how can I use a generic code snippet for Http public key pinning for various domain and various environment.
ssl https websecurity
add a comment |
I've added below section in my httpd conf file to support public key pinning for my website:
Header set Public-Key-Pins "pinsha256="my_public_keyhash_generatedfrom_mycertificate.crt"; max-age=31536000; includeSubDomains"
Tomorrow if I change my certificate , I've to hard code the new public key here, how can I use a generic code snippet for Http public key pinning for various domain and various environment.
ssl https websecurity
What is a generic code snippet in that context? By definition, each time you change your key (not necessarily each time you change your certificate, you can renew certificates using same key) you will need to change your header. Note that for multiple reasons, browsers are not in love anymore with HPKP so you might need to assess if you really need to use it or not.
– Patrick Mevzek
Mar 25 at 16:11
Thanks for this update. So each time if I'm changing the certificate I've to update the public hash accordingly and there's no way around to this.
– Saurabh Kumar
Mar 26 at 11:51
That is not true: again, you can renew a certificate without changing the public key it is based on. See--reuse-key
option incertbot
for example.
– Patrick Mevzek
Mar 26 at 14:59
add a comment |
I've added below section in my httpd conf file to support public key pinning for my website:
Header set Public-Key-Pins "pinsha256="my_public_keyhash_generatedfrom_mycertificate.crt"; max-age=31536000; includeSubDomains"
Tomorrow if I change my certificate , I've to hard code the new public key here, how can I use a generic code snippet for Http public key pinning for various domain and various environment.
ssl https websecurity
I've added below section in my httpd conf file to support public key pinning for my website:
Header set Public-Key-Pins "pinsha256="my_public_keyhash_generatedfrom_mycertificate.crt"; max-age=31536000; includeSubDomains"
Tomorrow if I change my certificate , I've to hard code the new public key here, how can I use a generic code snippet for Http public key pinning for various domain and various environment.
ssl https websecurity
ssl https websecurity
asked Mar 25 at 10:21
Saurabh KumarSaurabh Kumar
145 bronze badges
145 bronze badges
What is a generic code snippet in that context? By definition, each time you change your key (not necessarily each time you change your certificate, you can renew certificates using same key) you will need to change your header. Note that for multiple reasons, browsers are not in love anymore with HPKP so you might need to assess if you really need to use it or not.
– Patrick Mevzek
Mar 25 at 16:11
Thanks for this update. So each time if I'm changing the certificate I've to update the public hash accordingly and there's no way around to this.
– Saurabh Kumar
Mar 26 at 11:51
That is not true: again, you can renew a certificate without changing the public key it is based on. See--reuse-key
option incertbot
for example.
– Patrick Mevzek
Mar 26 at 14:59
add a comment |
What is a generic code snippet in that context? By definition, each time you change your key (not necessarily each time you change your certificate, you can renew certificates using same key) you will need to change your header. Note that for multiple reasons, browsers are not in love anymore with HPKP so you might need to assess if you really need to use it or not.
– Patrick Mevzek
Mar 25 at 16:11
Thanks for this update. So each time if I'm changing the certificate I've to update the public hash accordingly and there's no way around to this.
– Saurabh Kumar
Mar 26 at 11:51
That is not true: again, you can renew a certificate without changing the public key it is based on. See--reuse-key
option incertbot
for example.
– Patrick Mevzek
Mar 26 at 14:59
What is a generic code snippet in that context? By definition, each time you change your key (not necessarily each time you change your certificate, you can renew certificates using same key) you will need to change your header. Note that for multiple reasons, browsers are not in love anymore with HPKP so you might need to assess if you really need to use it or not.
– Patrick Mevzek
Mar 25 at 16:11
What is a generic code snippet in that context? By definition, each time you change your key (not necessarily each time you change your certificate, you can renew certificates using same key) you will need to change your header. Note that for multiple reasons, browsers are not in love anymore with HPKP so you might need to assess if you really need to use it or not.
– Patrick Mevzek
Mar 25 at 16:11
Thanks for this update. So each time if I'm changing the certificate I've to update the public hash accordingly and there's no way around to this.
– Saurabh Kumar
Mar 26 at 11:51
Thanks for this update. So each time if I'm changing the certificate I've to update the public hash accordingly and there's no way around to this.
– Saurabh Kumar
Mar 26 at 11:51
That is not true: again, you can renew a certificate without changing the public key it is based on. See
--reuse-key
option in certbot
for example.– Patrick Mevzek
Mar 26 at 14:59
That is not true: again, you can renew a certificate without changing the public key it is based on. See
--reuse-key
option in certbot
for example.– Patrick Mevzek
Mar 26 at 14:59
add a comment |
0
active
oldest
votes
Your Answer
StackExchange.ifUsing("editor", function ()
StackExchange.using("externalEditor", function ()
StackExchange.using("snippets", function ()
StackExchange.snippets.init();
);
);
, "code-snippets");
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "1"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55335609%2fhow-to-fix-http-public-key-pinning-issue-with-a-generic-code%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
0
active
oldest
votes
0
active
oldest
votes
active
oldest
votes
active
oldest
votes
Thanks for contributing an answer to Stack Overflow!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55335609%2fhow-to-fix-http-public-key-pinning-issue-with-a-generic-code%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
What is a generic code snippet in that context? By definition, each time you change your key (not necessarily each time you change your certificate, you can renew certificates using same key) you will need to change your header. Note that for multiple reasons, browsers are not in love anymore with HPKP so you might need to assess if you really need to use it or not.
– Patrick Mevzek
Mar 25 at 16:11
Thanks for this update. So each time if I'm changing the certificate I've to update the public hash accordingly and there's no way around to this.
– Saurabh Kumar
Mar 26 at 11:51
That is not true: again, you can renew a certificate without changing the public key it is based on. See
--reuse-key
option incertbot
for example.– Patrick Mevzek
Mar 26 at 14:59