Project

General

Profile

Actions

Regression #14678

closed

CA and Certificate renewal page does not properly list some SHA1 certificates as being weak

Added by Jim Pingle over 1 year ago. Updated about 1 year ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Certificates
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
23.09
Release Notes:
Default
Affected Version:
2.7.0
Affected Architecture:

Description

Noticed this when working on other OpenSSL changes, but some certificates are not being flagged by the renewal page as being weak. The "Would change" column says "No" when it should say "Yes". The most obvious example here is one with a digest listed as "RSA-SHA1". It's being converted to lowercase but the list it's being checked against is mixed case.

This can also affect the renewal process.

I'm fixing this along with other changes for #14672 and #14677


Files

clipboard-202308130917-dcyaf.png (4.61 KB) clipboard-202308130917-dcyaf.png aleksei prokofiev, 08/13/2023 06:17 AM
clipboard-202308140817-ouwpr.png (22.9 KB) clipboard-202308140817-ouwpr.png Jim Pingle, 08/14/2023 12:17 PM
clipboard-202308140818-jbf8s.png (38.2 KB) clipboard-202308140818-jbf8s.png Jim Pingle, 08/14/2023 12:18 PM
Actions

Also available in: Atom PDF