URL: https://github.com/SSSD/sssd/pull/837
Title: #837: p11_child: make OCSP digest configurable

dpward commented:
"""
@alexey-tikhonov I think you are getting a few things confused here.

The FIPS requirement you referenced is for **cryptographic** hashes. This pull 
request did not change _cryptographic_ hashing behavior. Instead, it changed 
how an OCSP request _identifies_ a certificate that the OCSP responder needs to 
validate. That is independent of which algorithm is used to _cryptographically 
sign_ the OCSP response that is returned (or optionally, the OCSP request that 
is sent).

In addition, some OCSP responders (including Microsoft's) implement RFC 5019, 
which places additional restrictions on how OCSP is used. In particular, 
[Section 2.1.1](https://tools.ietf.org/html/rfc5019#section-2.1.1) states that 
for OCSP requests,
```
   Clients MUST use SHA1 as the hashing algorithm for the
   CertID.issuerNameHash and the CertID.issuerKeyHash values.
```
So the change here actually breaks compatibility with RFC 5019 responders 
out-of-the-box. The fact that this hashing algorithm is configurable in SSSD is 
fine, but the default should be changed back to SHA-1. Again, this is not a 
_cryptographic_ hash.

---

As an aside, you might wish to add the [Preferred Signature Algorithms 
extension](https://tools.ietf.org/html/rfc6960#section-4.4.7) to outgoing OCSP 
requests instead.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/837#issuecomment-673709907
_______________________________________________
sssd-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]

Reply via email to