b85d6ec434
* Allow OCSP to use issuer's RevocationSigAlgo When an issuer specifies a RevocationSigAlgo, we should largely follow this for both CRLs and OCSP. However, x/crypto/ocsp lacks support for PSS signatures, so we drop these down to PKCS#1v1.5 instead. Signed-off-by: Alexander Scheel <alex.scheel@hashicorp.com> * Add warning when issuer has PSS-based RevSigAlgo Signed-off-by: Alexander Scheel <alex.scheel@hashicorp.com> * Add note about OCSP and PSS support Signed-off-by: Alexander Scheel <alex.scheel@hashicorp.com> Signed-off-by: Alexander Scheel <alex.scheel@hashicorp.com> |
||
---|---|---|
.. | ||
databases | ||
identity | ||
key-management | ||
kv | ||
pki | ||
ssh | ||
transform | ||
transit | ||
ad.mdx | ||
alicloud.mdx | ||
aws.mdx | ||
azure.mdx | ||
consul.mdx | ||
cubbyhole.mdx | ||
gcp.mdx | ||
gcpkms.mdx | ||
index.mdx | ||
kmip-profiles.mdx | ||
kmip.mdx | ||
kubernetes.mdx | ||
ldap.mdx | ||
mongodbatlas.mdx | ||
nomad.mdx | ||
rabbitmq.mdx | ||
terraform.mdx | ||
totp.mdx | ||
venafi.mdx |