chromium / badssl.com

:lock: Memorable site for testing clients against bad SSL configs.
https://badssl.com
Apache License 2.0
2.78k stars 186 forks source link

feature request: a site that sends a stapled OCSP response that uses sha-2 in the CertID #486

Open mozkeeler opened 2 years ago

mozkeeler commented 2 years ago

See https://bugzilla.mozilla.org/show_bug.cgi?id=1745600 and https://bugzilla.mozilla.org/show_bug.cgi?id=966856. Recently some sites began stapling OCSP responses that made use of sha-2 in the CertID section (sha-1 is much more common here). Since not all of the machines in the CDNs of the affected sites did use sha-2, it made it hard to verify the fix. It would be helpful to have a site that's guaranteed to be serving an OCSP response with a CertID that uses sha-2.