• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Signing CSR With Weak Algorithms

Scheduled Pinned Locked Moved General pfSense Questions
3 Posts 2 Posters 438 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    TerraNullis
    last edited by Sep 11, 2017, 11:58 AM

    Upgraded from pfSense 2.3 -> 2.4 to be able to comfortably sign CSRs through the GUI.
    And that functionality is there and im all happy about it!
    but theres a BUT!

    Cert_manager is signing the CSRs with a SHA1 digest. which by todays standards is weak. and google reports on it furiously with red paint all over the page.

    Is there any possibility to sign CSRs with a stronger algorithm (sha2(+)) in the GUI?

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Sep 11, 2017, 5:43 PM

      You are right, there should be a field for that but there isn't.

      I opened https://redmine.pfsense.org/issues/7853 and I have some code ready to push to add it in, plus display the digest algo in the infoblock for each cert.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • T
        TerraNullis
        last edited by Sep 12, 2017, 7:37 AM

        tbh, that was a stupid fast integration, thanks alot for a great product and awesome response!

        1 Reply Last reply Reply Quote 0
        1 out of 3
        • First post
          1/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received