3 ms·
I believe 384 has the same problem: most CAs use RSA-2048/SHA-256 signatures and very few do 2048/384 (which this certificate is doing), especially on demand (A
by cipherboy 4y ago
I believe 384 has the same problem: most CAs use RSA-2048/SHA-256 signatures and very few do 2048/384 (which this certificate is doing), especially on demand (ACME has no parameter to control hash function selection by the requester for instance)
SHA384 with P-384 is much more common (and tested elsewhere on the site); what is unique about this one is using a larger hash with RSA keys.
Like some of the other certs, it requires partnerships with CAs willing to bend their process a little for the sake of publicly available test infra.