# Need SHA-1 Certs

**URL:** <https://community.letsencrypt.org/t/need-sha-1-certs/24249>\
**Category:** Help\
**Created:** [December 16, 2016, 4:49pm UTC](https://community.letsencrypt.org/t/need-sha-1-certs/24249 "2016-12-16T16:49:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rannday](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rannday/32/10056_2.png) [@rannday](https://community.letsencrypt.org/u/rannday)\
**Post date:** [December 16, 2016, 4:49pm UTC](https://community.letsencrypt.org/t/need-sha-1-certs/24249/1 "2016-12-16T16:49:07Z")

</div>

My company has an older Cisco mesh network in need of new certs, but the APs only support SHA-1. We don’t want to update these devices because sometime next year we plan on upgrading all of them to Ruckus.

No CAs are offering SHA-1s. I’m at a loss on what I can do. Can I make SHA-1 certs with this tool? If not, does anybody here have a recommendation for how I can get some?

Thanks

---

<div class="post-metadata">

**Author:** ![pfg](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/pfg/32/1924_2.png) [@pfg](https://community.letsencrypt.org/u/pfg)\
**Post date:** [December 16, 2016, 5:04pm UTC](https://community.letsencrypt.org/t/need-sha-1-certs/24249/2 "2016-12-16T17:04:57Z")

</div>

Publicly-trusted CAs are not allowed to issue SHA-1 certificates; that includes Let’s Encrypt. They would risk being distrusted by browsers if they ignore this (see the WoSign story quite recently).

Depending on your use-case (and assuming you have no way to expedite the migration to devices that support SHA-2), you basically have two options:

- Use self-signed certificates or an internal CA. `openssl` will happily produce a SHA-1 certificate.
- Some CAs offer SHA-1 certificates issued under roots that have originally been publicly-trusted, but have since been removed from root programs and are not in scope for the rules that prevent SHA-1 issuance anymore. I know Comodo does this, and there might be others. I’m not sure whether they offer this to the general public or just at a certain enterprise client level (one company they do this for is Cloudflare, for example). Note that these certificates would not be trusted by any up-to-date browsers - not sure if this matters for your use-case. In fact, most browsers will stop trusting SHA-1 certificates entirely starting in January/February.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [December 16, 2016, 5:10pm UTC](https://community.letsencrypt.org/t/need-sha-1-certs/24249/3 "2016-12-16T17:10:50Z")

</div>

@rannday, @pfg is quite right that we’re not allowed to issue these certificates from our intermediate. Do you have the ability to add additional root certificates to your equipment? (Do they have some kind of management interface that lets you edit their CA trust list?) If so, you could make your own private root and issue SHA-1 certificates under it, and tell your APs to trust that root.

Among other possibilities, the `openssl` command can do this; I think learning about that should take somewhere between 30 minutes and 12 hours, depending on your prior level of experience with certificates and system administration.

---

<div class="post-metadata">

**Author:** ![rannday](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rannday/32/10056_2.png) [@rannday](https://community.letsencrypt.org/u/rannday)\
**Post date:** [December 16, 2016, 6:52pm UTC](https://community.letsencrypt.org/t/need-sha-1-certs/24249/4 "2016-12-16T18:52:01Z")

</div>

I"m going to research setting up our own CA. This is our only option, I’m afraid. By the time we got done updating all the APs firmware, it’ll probably be time to start replacing them with Ruckus.

Going to use this guide - [https://jamielinux.com/docs/openssl-certificate-authority/](https://jamielinux.com/docs/openssl-certificate-authority/)

Thanks for your help!

---

<div class="post-metadata">

**Author:** ![ahaw021](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ahaw021/32/14882_2.png) [@ahaw021](https://community.letsencrypt.org/u/ahaw021)\
**Post date:** [December 18, 2016, 10:41am UTC](https://community.letsencrypt.org/t/need-sha-1-certs/24249/5 "2016-12-18T10:41:34Z")

</div>

hi rannday

if you are using microsoft then you can use the active directory certificate services.

**NOTE:** one of the things about using an internal CA is the need to distribute their intermediates.

Microsoft gives you a way to distribute these via AD

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [January 17, 2017, 10:41am UTC](https://community.letsencrypt.org/t/need-sha-1-certs/24249/6 "2017-01-17T10:41:35Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
