Jump to content

Update for HOW TO: NGINX Reverse Proxy


Recommended Posts

darkassassin07
Posted (edited)

In this (locked) topic when setting up public key pinning there is info missing that will cause this header to be ignored by browsers:

 

As far as I understand from reading Public Key Pinning: Your doing it wrong you must pin a backup key along side your cert chain keys (IE pin at least one key that doesn't match your certs). Without it your pins are ignored and you may as well have not added it at all.

Edited by darkassassin07
Posted

thanks @@darkassassin07

 

I will take a look. I think the guide is a bit out of date aswell so does need a overhaul 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...