Can someone pls raise my learning curve.
I test my certificate with About the email test and I just read this (translated from Dutch)
Certificate generated thru dehydrated-0.7.2_1
-- quote --
The public key of at least one of your mail server certificates is based on a signing algorithm with parameters that should be phased out because they are weaker, although you can still use them if absolutely necessary. They will likely be insufficient in a future update.
Mail server (MX)|Deprecated signature parameter:
devrijegeest.nl | YR1: RSAPublicKey-2048 | ...to be phased out
Test explanation:
We test whether the public key of your mail server certificate and of every intermediate certificate is based on a secure signing algorithm with secure parameters. Digital signatures are used during certificate verification. The public key of a certificate can be used to verify that a signature was created using the corresponding private key.
Signing algorithm:
The signing algorithm is determined when the certificate is generated. A certificate can contain only one signing algorithm. It is possible to support more than one algorithm by configuring multiple certificates on a single server. Only the signing algorithms ECDSA, RSA, and EdDSA are considered sufficiently secure. In practice, EdDSA is rarely or never used. All algorithms are vulnerable to the quantum threat. For the time being, they offer sufficient protection. Quantum-safe alternatives are not yet part of the TLS standards.
--- end quote
Appreciate any reply and evt solution to this.
Thanks.