Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Recommended method for migrating from SHA1 cert to SHA512 cert

    Scheduled Pinned Locked Moved OpenVPN
    4 Posts 2 Posters 493 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jc2it
      last edited by jc2it

      In looking at the recent CE 2.7.1release documentation I realized we have a couple of old certs that need to migrate from SHA1 to SHA512 (SHA256 or higher). Anyone that has done this in the past with road warriors and OpenVPN how have you handled it well? Or what do you recommend avoiding?

      One method I was considering was to issue a new CA CERT and Server CERT and then place the new certificates on each road warrior system as a "backup" cert until it is needed in a couple of weeks.

      Is there a better way?

      Edit: Also, what am I forgetting?

      Thanks!

      1 Reply Last reply Reply Quote 1
      • J
        jc2it
        last edited by

        Would it be a better idea to Create Another CA with an updated cert and a New Server Cert and migrate all of the VPN clients as we can get them in?

        Anybody do this previously?

        1 Reply Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          If you have not yet upgraded to 2.7.1 or later, then creating a new CA + Server Cert + OpenVPN Server (+User Certs if you have them), and so on is ideal. You can then migrate users to that while both can still function.

          If you have already upgraded to 2.7.1 and the current server can't work because of the weak certs, then you're better off just creating the CA+Certs again and using them on the current server, then getting the new files to users and so on.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          J 1 Reply Last reply Reply Quote 0
          • J
            jc2it @jimp
            last edited by jc2it

            @jimp Thanks for the clarification. We have not upgraded to 2.7.1 and we will attempt to get that changed over seamlessly for the user.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.