Hi,
Can we please add to Let's Encrypt OCSP Responder support for SHA2 hashes in CertID.
Currently any OCSP requests that use SHA2 hashes in CertID receive an "unauthorized" reply (e.g. use -sha384 parameter with openssl ocsp command).
The OCSP Responder currently seems to support only SHA1 hashes.
This is more of a compliance issue.
SHA1 collision resistance has not been considered to be strong enough for a number of years.
Because of this, SHA1 has been dropped as an approved algorithm by Government and Industry regulators.
With support for SHA1 only, some places won't be able to use Let's Encrypt to meet their compliance requirements.