For HTTP Strict Transport Security
(HSTS
), there is a preload list, that site owners can submit their site to a list of domain names that the browser vendors ship their browsers with.
Are there any mechanisms similar to HSTS Preloading, that the site owners can "announce" the signature(s) of the public keys they will be using, so the browser knows what public keys to accept before its very first visit to that site?
I understand shipping a giant file with the public keys isn't practical, but I would be grateful if you could point me if there are any final or draft features that the site owners can announce them securely, and without making it possible for the rogue to trick clients to accept a public key that is not the actual key?