DigiCert: SHA-256 hash algorithm used with ECC P-384 key
The bug was raised because a certificate (OCSP) was reported to be signed using an ECC P-384 key while using ECDSA with SHA-256, contrary to the Mozilla policy requirement that P-384 signing keys must use ECDSA with SHA-384. The reporter cited Mozilla policy text and referenced a crt.sh entry for the certificate. DigiCert stated that the issue was already disclosed in another Bugzilla issue and requested that this bug be closed as a duplicate. The bug was subsequently marked as a duplicate of bug 1654967. The reporter later apologized for the duplicate and explained they had not found the original bug initially.
- A report was filed alleging an OCSP signature used ECDSA with SHA-256 despite being produced with an ECC P-384 key.
- The CA indicated the issue was already disclosed in an existing bug and the case was marked as a duplicate.
- Sectigo — The reporter cited Mozilla policy and said the OCSP signature uses ECDSA with SHA-256 even though it is signed by a P-384 key, noting it appeared to repeat Bug 1527423.
- DigiCert — Digicert stated the issue was already disclosed in bug 1654967 and asked to close this bug as a duplicate.
- Community commenter — The commenter acknowledged the duplicate and noted the bug was marked as a duplicate of bug 1654967.
- Sectigo — The reporter apologized and said they later found the original bug after searching Bugzilla more thoroughly.