On Wed, Oct 25, 2017 at 12:06 PM, Salz, Rich <rs...@akamai.com> wrote:

> > since those other means would be easier and more effective. You
>     have done nothing to suggest otherwise.
>
> Public-key pinning and CT seem like they would prevent those other
> mechanisms.  No?
>

Remember that non-default, user-installed root certificates are exempted
from those mechanisms in all current browsers.

--Richard



>
> _______________________________________________
> TLS mailing list
> TLS@ietf.org
> https://www.ietf.org/mailman/listinfo/tls
>
_______________________________________________
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls

Reply via email to