URL: https://github.com/SSSD/sssd/pull/837 Title: #837: p11_child: make OCSP digest configurable
alexey-tikhonov commented: """ > @alexey-tikhonov @sumit-bose I think you are getting a few things confused > here. ... > However, the hashes that are affected by this pull request are not used in a > _cryptographic_ manner. We [didn't confuse](https://github.com/SSSD/sssd/pull/837#issuecomment-506404695) those. But intention (perhaps wrong) was to get rid of sha-1 as much as possible as its widespread deprecation feels anticipated. > So using hash algorithms other than SHA-1 here breaks compatibility with RFC > 5019-compliant responders, which may refuse to even process the request (as > we are in fact seeing). Thanks for the reference. This is a strong point. > The issuer hash algorithm should remain a configuration option, but the > default should be reverted to SHA-1, which satisfies RFC 5019. Seems so. @simo5, do you agree? """ See the full comment at https://github.com/SSSD/sssd/pull/837#issuecomment-674802133
_______________________________________________ sssd-devel mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected]
