Conversation
There was a problem hiding this comment.
I like the idea of dropping ### HTTP Public Key Pinning and nested content. Agree with the Chrome stance and with your analysis of CAA's (lack of) value in the fed.
I could see some value in emphasizing CT, and would welcome suggestions of changes in that area, but I don't think it's worth presenting it as a way to prevent misissuance.
I think the section is valuable. I'll see if I can tweak language, but I actually don't have a huge issue with the way it's currently worded. Maybe just a shift to "auditing trustworthiness" versus "preventing misissuance"?
I actually kind of appreciate the introductory text under the FAQ heading as well. Specifically:
There is no simple and 100% effective way to force all browsers to only trust certificates for your domain that have been issued from a certain CA.
I think that's a valuable statement on its own, and there's no reason to remove it really, is there?
|
👍 I agree. I'll restore and tweak the CT text. |
|
Agree with @egyptiankarim, I think the CT section is helpful. I think there is value in at least mentioning HPKP, since you can more effectively dissuade its use by acknowledging it than by eliding over it. |
|
Agree with the above. Nothing much more for me to add. Will take another look when the tweaked version is pushed. |
|
Closed in favor of #239. |
This removes the section about how to prevent CAs from issuing for your domain. This is mostly inspired by Chrome announcing that they intend to remove HPKP, but in general I also think it is better for federal agencies to understand that there's really no reliable way to prevent issuance by CAs they didn't approve. Even CAA is a best-effort approach that doesn't protect against full compromise, and I am concerned that blunt application of CAA in the federal government is likely to lead to more harm than good.
So given that, I've proposed just removing this section entirely. I could see some value in emphasizing CT, and would welcome suggestions of changes in that area, but I don't think it's worth presenting it as a way to prevent misissuance.