Eventually we want to point our Tor Browser update URL directly to aus1.tpo and want to have the additional security gained through key pinning for cdn.tpo as well.
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Child items ...
Show closed items
Linked items 0
Link issues together to show that they're related.
Learn more.
This shouldn't be done at all till it's possible to pin the cert chain for aus1.tpo over a prolonged period of time (not the rather short 3 months imposed by the Let's Encrypt cert lifespan).WHile the scope of potential problems from not doing so should be limited to adversaries withholding updates (since the MARs are signed), that feels suboptimal.
Trac: Description: Eventually we want to point our Tor Browser update URL directly to aus1.tpo and want to have the additional security for cdn.tpo as well.
to
Eventually we want to point our Tor Browser update URL directly to aus1.tpo and want to have the additional security gained through key pinning for cdn.tpo as well. Summary: Pin certificates for aus1.tpo and cdn.tpo to Pin public keys for aus1.tpo and cdn.tpo
As Mike mentioned in #3555 (moved), there are different technologies of PK pinning. You can patch TBB yourself or ask Mozilla to extend FF's list. Sysadmins can only enable HPKP for you.