Laurie: Improving SSL certificate security
Laurie: Improving SSL certificate security
Posted Apr 10, 2011 18:47 UTC (Sun) by juhah (subscriber, #32930)In reply to: Laurie: Improving SSL certificate security by djao
Parent article: Laurie: Improving SSL certificate security
Few ideas how it might be further improved:
1. On first use, query pool of certificate fingerprint servers and check that others see what you see. Not a fool proof but helps in any case. Hard stop only if severs see different fingerprint. This has a potential privacy issue though.
2. Allow certificate to be updated without hard stop by caching fingerprint of next valid certificate immediately after storing the initial certificate. Hard stop if certificate changes and the new certificate fingerprint doesn't match the previously stored fingerprint.
