Skip to main content
Solved

SSL issue with SHA-2 Certificate

  • July 16, 2015
  • 4 replies
  • 31 views

Forum|alt.badge.img+14

Recently, our organization has undertaken an effort to replace all SHA-1 SSL certificates with SHA-2. Our Casper servers in test and production are on the list.

Concurrently with this, I observed that our Casper sites with SHA-1 certitificates would not open at all in Firefox 39 (current release) or in the Safari 9 beta. Both reference being unable to create a secure connections, with the Firefox error being more verbose (see picture).

My guess was upgrading the SSL certs to SHA-2 would address this issue, but it hasn't. Our certificate vendor is Comodo/InCommon and I imported their root CA, intermediate, and obviously the one for Tomcat into a new keystore. Has anyone gone through this process and have anything to share? I am going to engage with our security folks as well but wanted to inquire here first.

Thanks,
Bryan

Best answer by cmarker

Ran into the same issue, take a look at this post to change the ciphers used. Worked like a charm for us.

https://jamfnation.jamfsoftware.com/discussion.html?id=15032

4 replies

Forum|alt.badge.img+9
  • Contributor
  • Answer
  • July 16, 2015

Ran into the same issue, take a look at this post to change the ciphers used. Worked like a charm for us.

https://jamfnation.jamfsoftware.com/discussion.html?id=15032


Forum|alt.badge.img+14
  • Author
  • Contributor
  • July 16, 2015

Thanks for that. My search queries must not be great if I missed it.


bentoms
Forum|alt.badge.img+35
  • Hall of Fame
  • July 16, 2015

@powellbc Have a nose at this too.


Forum|alt.badge.img+14
  • Author
  • Contributor
  • July 17, 2015

Excellent, @bentoms, thanks for sharing! This is preferable to me as it comes straight from Jamf.