Global Information Lookup Global Information

HTTP Public Key Pinning information


HTTP Public Key Pinning (HPKP) is an obsolete Internet security mechanism delivered via an HTTP header which allows HTTPS websites to resist impersonation by attackers using misissued or otherwise fraudulent digital certificates.[1] A server uses it to deliver to the client (e.g. web browser) a set of hashes of public keys that must appear in the certificate chain of future connections to the same domain name.

For example, attackers might compromise a certificate authority, and then mis-issue certificates for a web origin. To combat this risk, the HTTPS web server serves a list of “pinned” public key hashes valid for a given time; on subsequent connections, during that validity time, clients expect the server to use one or more of those public keys in its certificate chain. If it does not, an error message is shown, which cannot be (easily) bypassed by the user.

The technique does not pin certificates, but public key hashes. This means that one can use the key pair to get a certificate from any certificate authority, when one has access to the private key. Also the user can pin public keys of root or intermediate certificates (created by certificate authorities), restricting site to certificates issued by the said certificate authority.

Due to HPKP mechanism complexity and possibility of accidental misuse (potentially causing a lockout condition by system administrators), in 2017 browsers deprecated HPKP and in 2018 removed its support in favor of Certificate Transparency.[2][3]

  1. ^ Evans, Chris; Palmer, Chris; Sleevi, Ryan (April 2015). Public Key Pinning Extension for HTTP. IETF. doi:10.17487/RFC7469. ISSN 2070-1721. RFC 7469.
  2. ^ Leyden, John (2017-10-30). "RIP HPKP: Google abandons public key pinning". The Register. Retrieved 2018-12-18.
  3. ^ Tung, Liam (2017-10-30). "Google: Chrome is backing away from public key pinning, and here's why". ZDNet. Retrieved 2018-12-18.

and 20 Related for: HTTP Public Key Pinning information

Request time (Page generated in 0.8402 seconds.)

HTTP Public Key Pinning

Last Update:

HTTP Public Key Pinning (HPKP) is an obsolete Internet security mechanism delivered via an HTTP header which allows HTTPS websites to resist impersonation...

Word Count : 1259

HTTP Strict Transport Security

Last Update:

Google-operated TLD included in the HSTS preload-list by default HTTP Public Key Pinning "Strict-Transport-Security". MDN Web Docs. Mozilla. Archived from...

Word Count : 2411

List of HTTP header fields

Last Update:

HTTP header Retrieved: 2012-02-09 W3C P3P Work Suspended "Public Key Pinning Extension for HTTP". IETF. Retrieved April 17, 2015. "Retry-After". HTTP...

Word Count : 2464

Pinning

Last Update:

Pinning may refer to: Pinning, the effect of certain weapons that cause their targets to be pinned down Pinning ceremony (nursing), a symbolic welcoming...

Word Count : 210

DNS Certification Authority Authorization

Last Update:

mechanisms, including Certificate Transparency to track mis-issuance, HTTP Public Key Pinning and DANE to block mis-issued certificates on the client-side, and...

Word Count : 1528

Cybersecurity information technology list

Last Update:

Negotiation of Keys Firewall (computing) Stateful firewall HTTPS HTTP Public Key Pinning Transport Layer Security TLS acceleration Network Security Services...

Word Count : 1792

Content Security Policy

Last Update:

Firefox HTTP Switchboard – user defined CSP rules, extension for Google Chrome and Opera HTTP Strict Transport Security HTTP Public Key Pinning Sid Stamm...

Word Count : 1780

List of RFCs

Last Update:

struck-through text. Internet Engineering Task Force, RFC Index (Text), http://www.ietf.org/download/rfc-index.txt RFC-Editor - Document Retrieval - search...

Word Count : 125

Derived unique key per transaction

Last Update:

used to encrypt PIN information acquired by Point-Of-Sale (POS) devices. DUKPT is not itself an encryption standard; rather it is a key management technique...

Word Count : 1774

Hardware security module

Last Update:

signing, the cryptographic material is asymmetric key pairs (and certificates) used in public-key cryptography. With other applications, such as data...

Word Count : 1996

Keystroke logging

Last Update:

can use keyloggers on public computers to steal passwords or credit card information. Most keyloggers are not stopped by HTTPS encryption because that...

Word Count : 5258

Scroll and Key

Last Update:

Object Viewer Archived 2011-04-30 at the Wayback Machine http://www.ivygateblog.com/?s=scroll+and+key, see membership lists A cross-reference with recent members...

Word Count : 1296

Transport Layer Security

Last Update:

instant messaging, and voice over IP, but its use in securing HTTPS remains the most publicly visible. The TLS protocol aims primarily to provide security...

Word Count : 17117

Web of trust

Last Update:

binding between a public key and its owner. Its decentralized trust model is an alternative to the centralized trust model of a public key infrastructure...

Word Count : 3392

Disc tumbler lock

Last Update:

locations like railroad and public utility installations. The original Abloy Classic design consists of a notched semi-cylindrical key, and a lock with detainer...

Word Count : 890

Boudoir photography

Last Update:

staple of the key stylistic components of pin and boudoir photography throughout the 20th century. Soldiers would keep mementos of pin up photos in their...

Word Count : 1880

Cryptography

Last Update:

use a "public key" to encrypt a message and a related "private key" to decrypt it. The advantage of asymmetric systems is that the public key can be freely...

Word Count : 10730

FinTS

Last Update:

FinTS-specification is publicly available on a website run by the ZKA (Central Credit Committee). Support for online-banking using PIN/TAN one time passwords...

Word Count : 456

Padlock

Last Update:

transactions is encrypted using public-key cryptography; some web browsers display a locked padlock icon while using the HTTPS protocol. Love locks are physical...

Word Count : 2021

Google Maps pin

Last Update:

Felt Google Maps Pin, 2010 Map, 2011 Project Google Birdhouse, 2012 Pin, 2013 http://pdfpiw.uspto.gov/50/209/D06/1.pdf [bare URL PDF] http://pimg-fpiw.uspto...

Word Count : 2532

PDF Search Engine © AllGlobal.net