1回答
- 新しい順
- 投票が多い順
- コメントが多い順
0
Amazon ACM (AWS Certificate Manager) does support OCSP (Online Certificate Status Protocol) for certificate validation. Regarding the hash algorithm used, ACM supports SHA-256 for generating the digital signature in the OCSP response. https://docs.aws.amazon.com/acm/
関連するコンテンツ
- AWS公式更新しました 2年前
- AWS公式更新しました 2年前
I have yet to see a request work with SHA256 OCSP request. Here is an openssl example:
openssl ocsp -issuer truststore.pem -sha256 -cert cert.pem -text -url http://ocsp.acm-pca.us-east-1.amazonaws.com
this failsopenssl ocsp -issuer truststore.pem -cert cert.pem -text -url http://ocsp.acm-pca.us-east-1.amazonaws.com
this succeeds (SHA1 default)So far every OCSP request made to ACM built with anything but SHA1 encoding fails. Is this a bug?