Hacker News new | past | comments | ask | show | jobs | submit login

I imagine things have only gotten "worse" with Let'sEncrypt issuing 90 certificates.



You pin a public key (of which the private key signs the leaf certificate, the sub-CA or the CA) with HPKP, not the certificate. With the default settings, LetsEncrypt re-uses the keypair for a new certificate.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: