1 個回答
- 最新
- 最多得票
- 最多評論
0
Amazon ACM (AWS Certificate Manager) does support OCSP (Online Certificate Status Protocol) for certificate validation. Regarding the hash algorithm used, ACM supports SHA-256 for generating the digital signature in the OCSP response. https://docs.aws.amazon.com/acm/
相關內容
- 已提問 1 年前
- 已提問 7 個月前
- AWS 官方已更新 2 年前
- AWS 官方已更新 2 年前
- AWS 官方已更新 2 年前
I have yet to see a request work with SHA256 OCSP request. Here is an openssl example:
openssl ocsp -issuer truststore.pem -sha256 -cert cert.pem -text -url http://ocsp.acm-pca.us-east-1.amazonaws.com
this failsopenssl ocsp -issuer truststore.pem -cert cert.pem -text -url http://ocsp.acm-pca.us-east-1.amazonaws.com
this succeeds (SHA1 default)So far every OCSP request made to ACM built with anything but SHA1 encoding fails. Is this a bug?