CVE-2004-2761 MD5 vulnerability in Security Analytics
search cancel

CVE-2004-2761 MD5 vulnerability in Security Analytics

book

Article ID: 280458

calendar_today

Updated On:

Products

Security Analytics

Issue/Introduction

2004-2761 : The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.

Resolution

CVE-2004-2761 involves using an md5 for a Certificate’s Signature Algorithm.

By default the SA uses SHA256.  Therefore, Security Analytics is not susceptible to this vulnerability.

 

Additional Information

The Certificate’s Signature Algorithm can be verified using a browser.

Instructions can be found on the web at:
I can see SHA-1 fingerprint/thumbprint on my certificate. Is my certificate actually SHA-2?