From: Matthias A. <mat...@gm...> - 2017-02-19 19:37:02
|
Am 15.02.2017 um 17:22 schrieb grarpamp: > Due to providers not rolling out certs simultaneously > across their entire infrastructure, and providers sometimes > having different certs depending on datacenter / admin / country... > sslfingerprint scheme needs to match any of multiple listed fingerprints > More on the subject is probably in my .rc and TLS certificate > tickets / posts somewhere. I am aware of your request, I just haven't written the code yet. Certificate verification is there today, only we need to see to getting TLS1.2 into a formal release that won't hicc-up the day TLS1.3 appears, and I'd like to know how you're certain that the fingerprint you see on your end is authoritative. Are your ISP faxing their finger prints to you? |