Unable to renew certificates, "Certificate uses weak signature hashing algorithm"
search cancel

Unable to renew certificates, "Certificate uses weak signature hashing algorithm"

book

Article ID: 406208

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

Exception caught for provided certificate - /root/vc_certs/en-vc_coecis_cornell_edu_interm.cer. Error: Certificate uses weak signature hashing algorithm - sha1. Only SHA-2 RSA algorithms are supported on the vCenter Server.

Environment

vCenter 8.0.x

Cause

SHA-1 certificates are not supported in vCenter 8, if they appear at any point in the certificate chain the certificate renewal will fail.

Resolution

If using Sectigo certificates, review the following articles:

https://knowledge.broadcom.com/external/article?articleNumber=312566

https://www.sectigo.com/faqs/detail/VMware-Center-Certificate-does-not-accept-the-SHA-1-root-certificate/kA0Uj0000002rB

Otherwise, please ensure you regenerate the certificate(s) within your chain, that are SHA-1.