AD FS - Signing/Decrypting cert and SHA-1 retirement
i presently use long life sha-1 cert ad fs 3.0 token signing/decrypting cert.
i'm aiming migrate sha-256 cert within next month can enlighten me official date might encounter issues because cert sha-1?
(plenty of information around code signing , ssl certs cant see definitive signing cert in ad fs ... possibly same code signing cert?)
also, have several relying party trusts sp cant handle second cert of course me smooth cert roll, manually update cert, how people handle this? guess have no choice co-ordinate sp's change same time?
cheers,
aengus
hiya aengusm,
yes, in case client applications cannot support multiple token signing certificates, handled in coordinated service window outside work hours - hurray! :/
on other hand, haven't had problems changing these certificates , have done few times now.
there no definite date when sha-1 certificates considered technically untrusted. practically considered unsafe certificates. should expect more changes on during 2016.
as different perspective, don't use certificates because things work certificates. use them secure traffic. when certificate no longer secures traffic, should replaced, because sole purpose :)
Windows Server > Directory Services
Comments
Post a Comment