Forum Discussion
Is it possible to generate a self-signed SSL certificate with SHA1 under version 11.6?
I have a weird issue where I need to set up a temporary certificate using the SHA1 hash. It looks like SHA2 is now used by default if the cert is generated from the GUI. I've trolled through the TMSH commands and I don't see where I can specify the signing hash using the console.
Is this doable? (I know SHA1 is deprecated; this isn't by my choice.)
3 Replies
- ltwagnonRet. Employee
Here's an article that might help: https://devcentral.f5.com/articles/big-ip-ssl-cipher-history
- rdessert_76127
Nimbostratus
Did you figure it out? I have an old application that requires SHA1 (not my choice as you stated) and it appears that the UI doesn't allow you to specify as you said. i doubt you can do it via the GUI, but this article can be used as a basis to do it via the CLI (not tmsh though)
http://support.f5.com/kb/en-us/solutions/public/7000/700/sol7754.html
i assume openssl will just default to sha-1, if not you might have to enforce that with the correct flag.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
