URL: https://github.com/SSSD/sssd/pull/837
Title: #837: p11_child: make OCSP digest configurable

alexey-tikhonov commented:
"""
> @alexey-tikhonov @sumit-bose I think you are getting a few things confused 
> here.
...
> However, the hashes that are affected by this pull request are not used in a 
> _cryptographic_ manner.

We [didn't 
confuse](https://github.com/SSSD/sssd/pull/837#issuecomment-506404695) those.

But intention (perhaps wrong) was to get rid of sha-1 as much as possible as 
its widespread deprecation feels anticipated.


> So using hash algorithms other than SHA-1 here breaks compatibility with RFC 
> 5019-compliant responders, which may refuse to even process the request (as 
> we are in fact seeing).

Thanks for the reference. This is a strong point.


> The issuer hash algorithm should remain a configuration option, but the 
> default should be reverted to SHA-1, which satisfies RFC 5019.

Seems so.

@simo5, do you agree?
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/837#issuecomment-674802133
_______________________________________________
sssd-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]

Reply via email to