Upgrade the Certificate Authority to SHA256

VMware recommends the certificate authorities to generate certificate using SHA256 and also in SSO LB document they mentioned not to use SHA 1 signature algorithm for SSL certificate. Pls find the below steps to upgrade the CA to SHA256.

Before doing any changes to the CA take the backup of the CA repository and SUB CAs

Certuil -backup \\share\backup

Certuil -backup \\Share\subbackup



Upgrade Certification Authority to SHA256

Open the Windows Powershell.

Enter the command:

certutil -setreg ca\csp\CNGHashAlgorithm SHA256

22CA (2)


Restart the service.



After the change CA will issue now SHA256 as Hash Algorithm and also we can renew CA to use SHA256.





Reference :







This entry was posted in Certificate, Windows and tagged , , , . Bookmark the permalink.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s