Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feature request: a site that sends a stapled OCSP response that uses sha-2 in the CertID #486

Open
mozkeeler opened this issue Dec 18, 2021 · 0 comments

Comments

@mozkeeler
Copy link

See https://bugzilla.mozilla.org/show_bug.cgi?id=1745600 and https://bugzilla.mozilla.org/show_bug.cgi?id=966856.
Recently some sites began stapling OCSP responses that made use of sha-2 in the CertID section (sha-1 is much more common here). Since not all of the machines in the CDNs of the affected sites did use sha-2, it made it hard to verify the fix. It would be helpful to have a site that's guaranteed to be serving an OCSP response with a CertID that uses sha-2.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant