amazon-archives / certlint

X.509 certificate linter
Apache License 2.0
157 stars 42 forks source link

Update SHA-1 rules for OCSP responder certs #52

Open alex opened 7 years ago

alex commented 7 years ago

https://github.com/awslabs/certlint/blob/7806b49251daca2d0b27c2acca8e925ad38b3bbf/lib/certlint/cablint.rb#L68-L70

For OCSP responder certs (which I guess we can detect with EKUs == [OCSP signing]) the cutoff date is 2017, instead of 2016.