ALERT: Some images may not load properly within the Knowledge Base Article. If you see a broken image, please right-click and select 'Open image in a new tab'. We apologize for this inconvenience.
Create a Certificate Signing Request (CSR) with an SHA-2 cryptographic hash function on the ProxySG
Article ID: 168258
Asset Management SolutionProxySG Software - SGOS
Starting in SGOS 22.214.171.124, you can specify the signing hash when you create the individual Certificate Signing Request (CSR). The following information is for SGOS versions 126.96.36.199 through 188.8.131.52.
CSRs on the ProxySG appliance are by default generated for use with an SHA-1 cryptographic hash function. Using the SHA-1 hash function is not an issue if you are requesting a certificate from the Certificate Authority (CA) because the CA applies the required hash function (SHA256) to the certificate when signing the CSR.
A hidden command exists that allows you to configure the appliance to use the SHA-2 hash function when creating a CSR. To change the default SHA-1 hash function to SHA-2, log in to the CLI and type the following commands:
>en #config t #(config)security default-signing-hash (sha1|sha256|sha512)