Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Miscellaneous improvements to profiles #212

Open
aarongable opened this issue Mar 20, 2024 · 0 comments · May be fixed by #228
Open

Miscellaneous improvements to profiles #212

aarongable opened this issue Mar 20, 2024 · 0 comments · May be fixed by #228
Assignees
Milestone

Comments

@aarongable
Copy link
Contributor

aarongable commented Mar 20, 2024

Section 7.1:

  • Subordinate: remove "Let's Encrypt Authority X", as those intermediates have expired
  • DV-SSL: specify that we only accept 3 specific RSA key sizes
  • OCSP: remove this profile entirely, as our only delegated OCSP signer has long since expired

Section 7.2:

  • Say that the signature algorithm is determined by the issuer
  • Add "onlyContainsUserCerts" to the IDP in the latter of the two profiles
aarongable added a commit that referenced this issue Sep 26, 2024
- Remove OCSP Delegated Responder profile, as we no longer issue such certificates
- Remove restrictions on the Common Names we set
- Remove restriction on ECDSA P-521
- Miscellaneous formatting and phrasing improvements

Fixes #185
Fixes #196
Fixes #212
Fixes #217
Fixes #218
@aarongable aarongable linked a pull request Sep 26, 2024 that will close this issue
@aarongable aarongable self-assigned this Sep 26, 2024
@aarongable aarongable added this to the Q3 2024 milestone Sep 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant