Important Notice: We're experiencing email notification issues. If you've posted a question in the community forums recently, please check your profile manually for responses while we're working to fix this.

On Monday the 3rd of March, around 5pm UTC (9am PT) users may experience a brief period of downtime while one of our underlying services is under maintenance.

Hilfe durchsuchen

Vorsicht vor Support-Betrug: Wir fordern Sie niemals auf, eine Telefonnummer anzurufen, eine SMS an eine Telefonnummer zu senden oder persönliche Daten preiszugeben. Bitte melden Sie verdächtige Aktivitäten über die Funktion „Missbrauch melden“.

Weitere Informationen

Wehave installed a new CA and now I get this error with the newly released certificates "SEC_ERROR_CERT_SIGNATURE_ALGORITHM_DISABLED"

  • 4 Antworten
  • 1 hat dieses Problem
  • 111 Aufrufe
  • Letzte Antwort von riccardo.perni

more options

we have upgraded our internal CA to sign CSR with SHA512 hashing and are using firefox quantum 60.4.0esr

can someone help me? Riccardo

we have upgraded our internal CA to sign CSR with SHA512 hashing and are using firefox quantum 60.4.0esr can someone help me? Riccardo

Geändert am von riccardo.perni

Ausgewählte Lösung

Do not worry, we have resolved the issue, it was related to the windows server 2016 default settings for the CA, it was selected the RSASSA-PSS algorithm for signing we have reconfigured it to use sha256RSA and now it working fine.

thank you for your support Riccardo

Diese Antwort im Kontext lesen 👍 0

Alle Antworten (4)

more options

hi, https://wiki.mozilla.org/index.php?title=SecurityEngineering/x509Certs suggests resigning the cert with a modern algorithm.

more options

Thank you for your help, but I do not think the algorithm used in signing is too old, I have done all this operation exactly because I got (with the old CA) the same error from Chrome (and Firefox did not complain), now with the new CA chrome (and explorer 11) accept the new certificate and Firefox start showing this error...

more options

can you provide a sample of a generated cert?

more options

Ausgewählte Lösung

Do not worry, we have resolved the issue, it was related to the windows server 2016 default settings for the CA, it was selected the RSASSA-PSS algorithm for signing we have reconfigured it to use sha256RSA and now it working fine.

thank you for your support Riccardo