What is HTTP Public Key Pinning and when to use it?

Technology CommunityCategory: Web SecurityWhat is HTTP Public Key Pinning and when to use it?
VietMX Staff asked 3 years ago

HTTP Public Key Pinning (HPKP) instructs a user agent to bind a site to specific root certificate authority, intermediate certificate authority, or end-entity public key. This prevents certificate authorities from issuing unauthorized certificates for a given domain that would nevertheless be trusted by the browsers.

Maximum risk sites must enable the use of HTTP Public Key Pinning (HPKP).