Public Key Pinning Extension for HTTP
RFC 7469, “Public Key Pinning Extension for HTTP”, is a Proposed Standard document published in April 2015 by C. Evans, C. Palmer, R. Sleevi. The canonical text is published by the RFC Editor.
Abstract
This document defines a new HTTP header that allows web host operators to instruct user agents to remember ("pin") the hosts' cryptographic identities over a period of time. During that time, user agents (UAs) will require that the host presents a certificate chain including at least one Subject Public Key Info structure whose fingerprint matches one of the pinned fingerprints for that host. By effectively reducing the number of trusted authorities who can authenticate the domain during the lifetime of the pin, pinning may reduce the incidence of man-in-the-middle attacks due to compromised Certification Authorities.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 7469 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7468 Textual Encodings of PKIX, PKCS, and CMS Structures
- RFC 7470 Conveying Vendor-Specific Constraints in the Path Computation Element Communication Protocol
- RFC 7467 URN Namespace for the North Atlantic Treaty Organization
- RFC 7471 OSPF Traffic Engineering Metric Extensions
- RFC 7466 An Optimization for the Mobile Ad Hoc Network Neighborhood Discovery Protocol
- RFC 7472 Internet Printing Protocol over HTTPS Transport Binding and the 'ipps' URI Scheme
- RFC 7465 Prohibiting RC4 Cipher Suites
- RFC 7473 Controlling State Advertisements of Non-negotiated LDP Applications