Ask HN: Thoughts on an alternative to Public Key Pinning (HPKP)?
Great! Except when you need to change your certificate of course.
They've added some workarounds whereby you can specify both a time duration and an alternate certificate, but as a small website operator, I need (want) to be able to make changes at any time, and I don't have my next certificate yet.
So what I really want is not to lock down a specific certificate, but make it so that I am the only one who can issue valid certificates for my site.
To achieve this, instead of pinning a specific public key, why not allow me to specify a self-signed root certificate with which I promise to also sign any HTTPS certificate?
I.e. any certificate presented for my site will be signed by a regular CA just as normal, but in addition to this, it will also be signed by my own home-brew certificate, as specified in a HPKP2 header.
This way, I can change my certificate any time, and Evil People will have to not only subvert a CA, they also have to get my private key, which I can keep as safe as I care / am able to.
This would be no more secure than current HPKP since it's still "trust on first visit", but should be easier for websites to deploy & maintain.
Thoughts?
(There were some threads recently on the abysmal uptake of HPKP among the top 1M sites, and it made me think of why I haven't implemented it on mine)