AD FS - Signing/Decrypting cert and SHA-1 retirement


i presently use long life sha-1 cert ad fs 3.0 token signing/decrypting cert.

i'm aiming migrate sha-256 cert within next month can enlighten me official date might encounter issues because cert sha-1?

(plenty of information around code signing , ssl certs cant see definitive signing cert in ad fs ... possibly same code signing cert?)

also, have several relying party trusts sp cant handle second cert of course me smooth cert roll, manually update cert, how people handle this? guess have no choice co-ordinate sp's change same time?

cheers,

aengus

hiya aengusm,

yes, in case client applications cannot support multiple token signing certificates, handled in coordinated service window outside work hours - hurray! :/

on other hand, haven't had problems changing these certificates , have done few times now.

there no definite date when sha-1 certificates considered technically untrusted. practically considered unsafe certificates. should expect more changes on during 2016.

as different perspective, don't use certificates because things work certificates. use them secure traffic. when certificate no longer secures traffic, should replaced, because sole purpose :)



Windows Server  >  Directory Services



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file