<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Does the browser recognize it in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-which-software-version-support-sha2-certificates-for-web/m-p/2577957#M41344</link>
    <description>&lt;P&gt;Does the browser recognize it as a SHA-1 or SHA-2?&amp;nbsp; Or, in other words, will this allow us to create certificates that will continue to function after IE and Chrome start rejection HTTPS web pages using SHA-1?&lt;/P&gt;</description>
    <pubDate>Mon, 16 May 2016 20:01:27 GMT</pubDate>
    <dc:creator>sestonenppd</dc:creator>
    <dc:date>2016-05-16T20:01:27Z</dc:date>
    <item>
      <title>WLC: which software-version support SHA2 certificates for Web Authentification and Web Management ?</title>
      <link>https://community.cisco.com/t5/wireless/wlc-which-software-version-support-sha2-certificates-for-web/m-p/2577953#M41340</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to install new SHA2 3th-Party certificates on our WLCs. There are old WiSM1-Boards and 2504 to support our old 1230 Access Points, running 7.0.251.2, which didn't install it,&amp;nbsp;although the config manual for 7.6 and 8.0 say that SHA2 certificates are supported since 7.0.250.0. When I tried to install the SHA2-certificates I get the message "File transfer failed" an the log says:&lt;/P&gt;&lt;P&gt;*TransferTask: Dec 12 13:22:14.394: #UPDATE-3-CERT_INST_FAIL: updcode.c:1869 Failed to install Webauth certificate. rc = 1&lt;BR /&gt;*TransferTask: Dec 12 13:22:14.394: #SSHPM-3-KEYED_PEM_DECODE_FAILED: sshpmcert.c:4085 Cannot PEM decode private key&lt;/P&gt;&lt;P&gt;I tried to install the same certificates on our WiSM2-Boards, running 7.4.121.0 and I failed too. The same certificates could be installed on a 2504 running 8.0.100 without any problems.&lt;/P&gt;&lt;P&gt;In all 3 cases I tried to install unchained certificates for web management and Level 3 chained certificates&amp;nbsp; for web authentication. I used the following guides to get the certificates (e.g. taken from the config manual 8.0.100):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html" target="_blank"&gt;http://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/70584-csr-wlc-00.pdf" target="_blank"&gt;http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/70584-csr-wlc-00.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which software versions support SHA2 certificates and which didn't ? Is the a list for it ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 09:07:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-which-software-version-support-sha2-certificates-for-web/m-p/2577953#M41340</guid>
      <dc:creator>Carsten Ruckelshausen</dc:creator>
      <dc:date>2021-07-05T09:07:13Z</dc:date>
    </item>
    <item>
      <title>Could be the bug : Need WLC</title>
      <link>https://community.cisco.com/t5/wireless/wlc-which-software-version-support-sha2-certificates-for-web/m-p/2577954#M41341</link>
      <description>&lt;P&gt;Could be the bug : Need WLC Support for SHA-256 #CSCup57577&lt;/P&gt;&lt;P&gt;Known affected release : 7.4(121.0)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2014 22:02:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-which-software-version-support-sha2-certificates-for-web/m-p/2577954#M41341</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-12-12T22:02:18Z</dc:date>
    </item>
    <item>
      <title>The WLC supports SHA-2</title>
      <link>https://community.cisco.com/t5/wireless/wlc-which-software-version-support-sha2-certificates-for-web/m-p/2577955#M41342</link>
      <description>&lt;P&gt;The WLC supports SHA-2 certificates since release 8.0.100, so at this moment this is the only release where this is supported on.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2014 23:33:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-which-software-version-support-sha2-certificates-for-web/m-p/2577955#M41342</guid>
      <dc:creator>Freerk Terpstra</dc:creator>
      <dc:date>2014-12-12T23:33:47Z</dc:date>
    </item>
    <item>
      <title>Hello, I solved the problem.</title>
      <link>https://community.cisco.com/t5/wireless/wlc-which-software-version-support-sha2-certificates-for-web/m-p/2577956#M41343</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I solved the problem. First I used a Debian Linux system with Openssl 1.0.1. After I searched the internet using one of the log messages above I found sites which mentioned to use Openssl 0.9.x. So I tried a productive and security fixes Debian Linux System running Openssl 0.9.8 and I succeeded. The wlcs accepted the certificate files and used it after a reboot. The Web GUI still shows a SHA1 Fingerprint, but the certificate signature Algorithm is SHA2:&lt;/P&gt;&lt;P&gt;Signature Algorithm: sha256WithRSAEncryption&lt;/P&gt;&lt;P&gt;When you check the openssl.org homepage Openssl 0.9.8 is still one of the actual version of openssl and is still available and fixed. But the Openssl Roadmap says:&lt;/P&gt;&lt;P&gt;"We don't want to have to maintain too many branches. This is likely to include a timescale for the EOL of version 0.9.8"&lt;/P&gt;&lt;P&gt;I don't know the differences between certificates made with openssl 0.9.8 and 1.0.1. Is there anybody who can explain it to me ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2014 08:00:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-which-software-version-support-sha2-certificates-for-web/m-p/2577956#M41343</guid>
      <dc:creator>Carsten Ruckelshausen</dc:creator>
      <dc:date>2014-12-16T08:00:55Z</dc:date>
    </item>
    <item>
      <title>Does the browser recognize it</title>
      <link>https://community.cisco.com/t5/wireless/wlc-which-software-version-support-sha2-certificates-for-web/m-p/2577957#M41344</link>
      <description>&lt;P&gt;Does the browser recognize it as a SHA-1 or SHA-2?&amp;nbsp; Or, in other words, will this allow us to create certificates that will continue to function after IE and Chrome start rejection HTTPS web pages using SHA-1?&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2016 20:01:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-which-software-version-support-sha2-certificates-for-web/m-p/2577957#M41344</guid>
      <dc:creator>sestonenppd</dc:creator>
      <dc:date>2016-05-16T20:01:27Z</dc:date>
    </item>
  </channel>
</rss>

