[websec] Fwd: [saag] Pinning

2012-06-05 Thread Paul Hoffman
From the SAAG mailing list, but appropriate here. I bet that Sean would appreciate all discussion to go on on the SAAG mailing list... Begin forwarded message: From: Sean Turner turn...@ieca.com Subject: [saag] Pinning Date: June 5, 2012 12:55:29 PM PDT To: s...@ietf.org All, There

Re: [websec] Pinning

2012-06-05 Thread Yoav Nir
Hi The similarity of pinning and DANE has been discussed before. DANE relies on DNSSEC being deployed, which key-pinning does not. Come to think of it, the draft needs a section comparing with DANE, but that's for another thread. draft-perrin-tls-tack seems to tackle the same problem as