← Back to release summary

HTTP Public Key Pinning violating reporting

Category
Security
Type
New or changed feature
Status
Enabled by default (Chrome 46)
Intent stage
None

Summary

HTTP Public Key Pinning (HPKP) allows websites to send an HTTP header that pins one or more of the public keys present in the site’s certificate chain. This feature tracks the implementation of HPKP reporting, which allows website owners to receive reports when the browser detects HPKP violations.

Standards & signals

Docs: https://developers.google.com/web/updates/2015/09/HPKP-reporting-with-chrome-46 https://docs.google.com/document/d/1hPMeG44li9hccIj4Jm2S3v1O_DEYnPsoiD4ZCzkAN8c/edit?usp=sharing https://developer.mozilla.org/en-US/docs/Web/Security/Public_Key_Pinning

View on chromestatus.com