Certificate Have problem when pci compliance testing on router


Hi @aididmazlan,

This isn’t very helpful without more information, like the domain, the specific error message, or what kind of PCI compliance test you’re doing.

If the PCI compliance scanner is complaining about the SHA-1 signature on the DST (IdenTrust) root certificate, the scanner vendor is misinterpreting the rules. We have three prior threads about this issue here on this forum; you can find the details in each of them.


I hope that helps!


its complain about TLS.


You’ll have to give us more information in order for us to help you. (For example, what domain name, what PCI compliance tester, and what error message?)


The error is "undefined CVE, X.509 certificate subject CN


There’s no reason for such an error to occur for a properly configured site using a Let’s Encrypt certificate.


“Notice that your merchant still using TLS v1.0 on port 8443” what about this ? can you help ?


That’s going to be your accepted TLS, you’ll have to see if whatever service running on port 8443 can be upgraded to disable TLS 1.0 and use 1.1 or 1.2.

Configs vary wildly depending on what it is. If it’s the pfsense webserver then try their forums for how to disable TLS 1.0


Right now I’m using asus webserver . can you advice how to config ?


