Verified Commit 967f23e6 authored by anarcat's avatar anarcat 💥
Browse files

note that HPKP will be removed, linking to ticket

parent 9528052e
Loading
Loading
Loading
Loading
+10 −2
Original line number Diff line number Diff line
@@ -83,9 +83,12 @@ Then remove the file.

## Enabling HPKP

HPKP is generally considered DEPRECATED. It has been [disabled in
Google Chrome in 2017][] and should generally not be used anymore.
Note: HPKP is generally considered DEPRECATED. It has been [disabled
in Google Chrome in 2017][] and should generally not be used
anymore. There are [plans to remove it completely][] in our
infrastructure.

[plans to remove it completely]: https://gitlab.torproject.org/tpo/tpa/team/-/issues/33592
[disabled in Google Chrome in 2017]: https://www.zdnet.com/article/google-chrome-is-backing-away-from-public-key-pinning-and-heres-why/

This section should generally be skipped unless you *really* need key
@@ -115,6 +118,11 @@ pinning for some obscure reason.

## Disabling HPKP

Note: HPKP is generally considered DEPRECATED. It has been [disabled
in Google Chrome in 2017][] and should generally not be used
anymore. There are [plans to remove it completely][] in our
infrastructure.

To disable key pinning ([HPKP][]) on a given domain, just remove the
backup key from the repository: