取消
显示结果 
搜索替代 
您的意思是: 
cancel
3271
查看次数
12
有帮助
1
回复

请教,关于停止使用“SHA-1 证书”对思科产品及应用的影响?

Pengfei Yu
Spotlight
Spotlight
大家,最近了解到有厂商将终止支持SHA-1 证书,新闻如下:
在Mozilla和微软之后,Google也考虑提前终止支持SHA-1 证书。随着计算能力的提升,伪造使用SHA-1哈希算法的证书所需的时间将会越来越少。三大浏览器开发商都同意终止支持2016年1月1日之后签发的SHA-1证书,到2017年1月1日终止支持所有SHA-1证书。
作为新人,我想请教此事件会对思科产品和应用产生什么影响,以及在思科安全应用上需要做哪些适应性调整?
1 个已接受解答

已接受的解答

taosun2
Cisco Employee
Cisco Employee
思科安全应用上已经有相关版本作示明确提示,例如:anyconnect ,详细如下:
http://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect41/release/notes/b_Release_Notes_AnyConnect_4_1.html
Guidelines and Limitations
Microsoft No Longer Supporting SHA-1
A secure gateway with a SHA-1 certificate is considered valid by a Windows endpoint until January 2017. After January 2017, Windows endpoints will no longer consider a secure gateway with a SHA-1 certificate as trusted. Ensure that your secure gateway does not have a SHA-1 identity certificate.
"Code Signing Certificates: Windows will no longer trust files with the Mark of the Web attribute that are signed with a SHA-1 code signing certificate and are timestamped after 1/1/2016." Refer to the Microsoft documentation for more details: here
Files signed before January 1st, 2016 will be valid until January 1st, 2017.
Note
Due to the code signing changes, the current AnyConnect users mustupgrade to 3.1.13011, the future version of 4.2 MR, or AnyConnect 4.3+ releases in order to keep their AnyConnect functional on Windows platforms after January 1st, 2017.

在原帖中查看解决方案

1 条回复1

taosun2
Cisco Employee
Cisco Employee
思科安全应用上已经有相关版本作示明确提示,例如:anyconnect ,详细如下:
http://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect41/release/notes/b_Release_Notes_AnyConnect_4_1.html
Guidelines and Limitations
Microsoft No Longer Supporting SHA-1
A secure gateway with a SHA-1 certificate is considered valid by a Windows endpoint until January 2017. After January 2017, Windows endpoints will no longer consider a secure gateway with a SHA-1 certificate as trusted. Ensure that your secure gateway does not have a SHA-1 identity certificate.
"Code Signing Certificates: Windows will no longer trust files with the Mark of the Web attribute that are signed with a SHA-1 code signing certificate and are timestamped after 1/1/2016." Refer to the Microsoft documentation for more details: here
Files signed before January 1st, 2016 will be valid until January 1st, 2017.
Note
Due to the code signing changes, the current AnyConnect users mustupgrade to 3.1.13011, the future version of 4.2 MR, or AnyConnect 4.3+ releases in order to keep their AnyConnect functional on Windows platforms after January 1st, 2017.
快捷链接