cancel
Showing results for 
Search instead for 
Did you mean: 

Secure Login Server and SHA256-based certificates

Former Member
0 Kudos

Hi guys,

can the SLS produce X.509 certificates that use SHA256 as their hash algorithm rather than SHA1 and/or MD5? During the certificate creation process (i.e. Create New Root CA) one can only specify the key length but not the hashing algorithm.

Thanks

Michael

Accepted Solutions (1)

Accepted Solutions (1)

former_member200373
Participant
0 Kudos

Hello Michael,

see the latest SP03 PL02 of SLS. We support SHA-2 and RSA-PSS as new algorithms.

We recommend SHA256, as SHA512 is not supported by all TLS clients.

-- Stephan

Former Member
0 Kudos

Servus Stephan, good to hear from you

Could you point me in the right direction in terms of documentation on how to do that please? A fresh install does not appear to be using SHA256, so I guess I need to make some config changes.

Thanks

Michael

former_member200373
Participant
0 Kudos

You should see a drop down list in User Certificate Configuration > User Certificate Properties > Signature Algorithm, providing SHA-1 and several SHA-2 with RSA.

The installation guide is not up-to-date yet, will be added for SP04.

Take care,

-- Stephan

Former Member
0 Kudos

awesome, thanks!

Answers (0)