URL: https://github.com/SSSD/sssd/pull/837
Title: #837: p11_child: make OCSP digest configurable

alexey-tikhonov commented:
"""
> > 
> > Could you please check if using `ocsp_dgst=sha1` helps?
> 
> Yes, we have proven that manually configuring the client does work around the 
> issue. It seems however that other implementations will fallback. I do 
> realize some of this is openSSL behavior, but this change may have broken 
> existing implementations, especially already deployed RHEL8 systems.

> I'm actually ok leaving this default as I'm working with those needed on my 
> side to advance OCSP forward, but mostly an FYSA based on the RH Bugzilla 
> comment stating that OCSP responders must have SHA2 enabled and ok to change 
> the default, which is an incorrect assumption.

You are right, there are some deployments that were broken.

But I think it's totally fine that admins will be made aware that their OCSP 
server uses (near to) deprecated SHA-1 and they need to configure this 
explicitly.

"""

See the full comment at 
https://github.com/SSSD/sssd/pull/837#issuecomment-672962573
_______________________________________________
sssd-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]

Reply via email to