Details
-
Improvement
-
Status: Resolved
-
Major
-
Resolution: Won't Fix
-
1.7.1
-
None
Description
HTTPS Public Key Pinning allows for explicit public keys to be transmitted to a client instructing the client to only trust those keys for the service. This should only be implemented in conjunction with a strong certificate management strategy, as pinning a public key that is later compromised or expired without having a backup can lead to clients being blocked from using the legitimate service.
More details on HPKP are available in RFC 7469.
Attachments
Issue Links
- relates to
-
NIFI-2437 Enforce HSTS to require HTTPS connections if available
- Resolved