badssl.com icon indicating copy to clipboard operation
badssl.com copied to clipboard

feature request: a site that sends a stapled OCSP response that uses sha-2 in the CertID

Open mozkeeler opened this issue 4 years ago • 0 comments

See https://bugzilla.mozilla.org/show_bug.cgi?id=1745600 and https://bugzilla.mozilla.org/show_bug.cgi?id=966856. Recently some sites began stapling OCSP responses that made use of sha-2 in the CertID section (sha-1 is much more common here). Since not all of the machines in the CDNs of the affected sites did use sha-2, it made it hard to verify the fix. It would be helpful to have a site that's guaranteed to be serving an OCSP response with a CertID that uses sha-2.

mozkeeler avatar Dec 18 '21 21:12 mozkeeler