<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Recommended method for migrating from SHA1 cert to SHA512 cert]]></title><description><![CDATA[<p dir="auto">In looking at the recent CE 2.7.1release documentation I realized we have a couple of old certs that need to migrate from SHA1 to SHA512 (SHA256 or higher). Anyone that has done this in the past with road warriors and OpenVPN how have you handled it well? Or what do you recommend avoiding?</p>
<p dir="auto">One method I was considering was to issue a new CA CERT and Server CERT and then place the new certificates on each road warrior system as a "backup" cert until it is needed in a couple of weeks.</p>
<p dir="auto">Is there a better way?</p>
<p dir="auto">Edit: Also, what am I forgetting?</p>
<p dir="auto">Thanks!</p>
]]></description><link>https://forum.netgate.com/topic/184439/recommended-method-for-migrating-from-sha1-cert-to-sha512-cert</link><generator>RSS for Node</generator><lastBuildDate>Thu, 16 Apr 2026 04:41:46 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/184439.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 28 Nov 2023 23:20:18 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Recommended method for migrating from SHA1 cert to SHA512 cert on Fri, 01 Dec 2023 17:03:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jimp">@<bdi>jimp</bdi></a> Thanks for the clarification. We have not upgraded to 2.7.1 and we will attempt to get that changed over seamlessly for the user.</p>
]]></description><link>https://forum.netgate.com/post/1139603</link><guid isPermaLink="true">https://forum.netgate.com/post/1139603</guid><dc:creator><![CDATA[jc2it]]></dc:creator><pubDate>Fri, 01 Dec 2023 17:03:22 GMT</pubDate></item><item><title><![CDATA[Reply to Recommended method for migrating from SHA1 cert to SHA512 cert on Fri, 01 Dec 2023 16:48:45 GMT]]></title><description><![CDATA[<p dir="auto">If you have not yet upgraded to 2.7.1 or later, then creating a new CA + Server Cert + OpenVPN Server (+User Certs if you have them), and so on is ideal. You can then migrate users to that while both can still function.</p>
<p dir="auto">If you have already upgraded to 2.7.1 and the current server can't work because of the weak certs, then you're better off just creating the CA+Certs again and using them on the current server, then getting the new files to users and so on.</p>
]]></description><link>https://forum.netgate.com/post/1139595</link><guid isPermaLink="true">https://forum.netgate.com/post/1139595</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Fri, 01 Dec 2023 16:48:45 GMT</pubDate></item><item><title><![CDATA[Reply to Recommended method for migrating from SHA1 cert to SHA512 cert on Fri, 01 Dec 2023 16:05:08 GMT]]></title><description><![CDATA[<p dir="auto">Would it be a better idea to Create Another CA with an updated cert and a New Server Cert and migrate all of the VPN clients as we can get them in?</p>
<p dir="auto">Anybody do this previously?</p>
]]></description><link>https://forum.netgate.com/post/1139573</link><guid isPermaLink="true">https://forum.netgate.com/post/1139573</guid><dc:creator><![CDATA[jc2it]]></dc:creator><pubDate>Fri, 01 Dec 2023 16:05:08 GMT</pubDate></item></channel></rss>