aarongable / draft-acme-ari

Internet Draft for the Automated Certificate Management Environment (ACME) Renewal Information (ARI) Extension
Other
4 stars 7 forks source link

Include justification of sha1 in Security Considerations #16

Closed aarongable closed 2 years ago

aarongable commented 2 years ago

The choice to mandate sha1 for the issuer name hash and issuer key hash is based on rfc5019 "Lightweight OCSP Profile" and the fact that the purpose of the hash is non-cryptographic. Include a sentence or two with this same info in the security considerations section.

aarongable commented 2 years ago

Closing this because we're moving away from SHA1 (see #17)