Skip to content

Please require SHA256 usage for OCSP responses for issuer Name and Key hashes #614

@xnox

Description

@xnox

Current requirements:

OCSP responders operated by the CA SHALL support the HTTP GET method, as described in RFC 6960 and/or RFC 5019. The CA MAY process the Nonce extension (1.3.6.1.5.5.7.48.1.2) in accordance with RFC 8954.

RFC 6960 supports different hashes.
RFC 5019 requires SHA1.

In anticipation of https://datatracker.ietf.org/doc/draft-ietf-lamps-rfc5019bis/ getting published please consider starting a ballot to require SHA256 to be used instead of SHA1.

Metadata

Metadata

Assignees

No one assigned

    Labels

    simpleNon controversial topic ready for ballot

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions