When will the switch to the new intermediates happen? [re: static pins for torproject.org]

We don't have the exact date set - we're waiting on a cross-sign from IdenTrust, but it will be sometime this fall. I would recommend getting a fresh set of certificates now and again in two weeks.

A couple of thoughts about your pins: It looks like you have three backup keys in your pinset: Tor1, Tor2, and Tor3. Is there anything that would prevent you from using one of those backup keys after we switch to R3?

Also, it would be less risky to pin roots (DST Root X3, ISRG Root X1, and now ISRG Root X2) than intermediates, since we intend to rotate intermediates on a more regular basis in the future.

We don't currently have official guidance on whether or how to use HPKP, but note that it has increasingly been a source of issues in the WebPKI:

https://groups.google.com/forum/#!forum/mozilla.dev.security.policy (search for "hpkp" - direct links to searches are broken right now and require login)
https://blog.entrust.com/2017/10/http-public-key-pinning-or-hpkp-no-longer-a-good-idea/

3 Likes