The 
Certificate Transparency is probably something Hubzilla should/could use?
It is a measure to prevent (or try to prevent) that a third party (man in the middle) could steal and use a certificate from the original server.
Example
Expect-CT: enforce, max-age=21600I just found it in 
security blog.