Replies: 2 comments 1 reply
|
Hi @fdeantoni, thanks for the detailed writeup. In order to figure the right priority for this, can you clarify whether this is causing you an actual production problem, or is the impact limited to |
|
As far as I can tell this is a check-only restriction, not a proxy limitation. The P-256 test lives in one place, |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Hi All,
I see in the code that P-256 + ecdsa-with-SHA256 is enforced:
linkerd2/pkg/issuercerts/issuercerts.go
Lines 174 to 188 in 3af2f45
This can pose a problem if a company has a strict policy to only allow P-384.
Is there a specific reason P-256 is enforced? If I create a PR to support P-384 + ecdsa-with-SHA384, is there a chance it will get merged?
Note that this policy seems to be only enforced in the CLI check. Things seem to work perfectly fine on the cluster when using a trust anchor with P-384 + ecdsa-with-SHA384.
All reactions