1개 답변
- 최신
- 최다 투표
- 가장 많은 댓글
0
Amazon ACM (AWS Certificate Manager) does support OCSP (Online Certificate Status Protocol) for certificate validation. Regarding the hash algorithm used, ACM supports SHA-256 for generating the digital signature in the OCSP response. https://docs.aws.amazon.com/acm/
관련 콘텐츠
- AWS 공식업데이트됨 2년 전
I have yet to see a request work with SHA256 OCSP request. Here is an openssl example:
openssl ocsp -issuer truststore.pem -sha256 -cert cert.pem -text -url http://ocsp.acm-pca.us-east-1.amazonaws.com
this failsopenssl ocsp -issuer truststore.pem -cert cert.pem -text -url http://ocsp.acm-pca.us-east-1.amazonaws.com
this succeeds (SHA1 default)So far every OCSP request made to ACM built with anything but SHA1 encoding fails. Is this a bug?