URL: https://github.com/SSSD/sssd/pull/837 Title: #837: p11_child: make OCSP digest configurable
alexey-tikhonov commented: """ > > > > Could you please check if using `ocsp_dgst=sha1` helps? > > Yes, we have proven that manually configuring the client does work around the > issue. It seems however that other implementations will fallback. I do > realize some of this is openSSL behavior, but this change may have broken > existing implementations, especially already deployed RHEL8 systems. > I'm actually ok leaving this default as I'm working with those needed on my > side to advance OCSP forward, but mostly an FYSA based on the RH Bugzilla > comment stating that OCSP responders must have SHA2 enabled and ok to change > the default, which is an incorrect assumption. You are right, there are some deployments that were broken. But I think it's totally fine that admins will be made aware that their OCSP server uses (near to) deprecated SHA-1 and they need to configure this explicitly. """ See the full comment at https://github.com/SSSD/sssd/pull/837#issuecomment-672962573
_______________________________________________ sssd-devel mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected]
