cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
471
Views
5
Helpful
3
Replies

Does anyone know if Cisco Clean Access Server version 4.1(8) supports SHA-256 signed SSL certificates?

Rafael Sanchez
Level 1
Level 1

Yes I know these are very old servers and technically we should move away from CAS altogether. But unfortunately this is an environment i inherited and am now dealing with the issues.  Due to the requirement to move away from sha-1 signed certificates I need to replace my current certs with sha-256 signed certs.  But before I do that I want to know if anyone knows if CAS version 4.1(8) supports SHA-256 certs?  I did check the release notes but there is no mention of the supported SHA versions, etc.  I tried TAC but no joy there either, etc. 

1 Accepted Solution

Accepted Solutions

Jatin Katyal
Cisco Employee
Cisco Employee

Hello Rafael,

SHA-2 signed certificate support was added in 4.7.2 for CAS and CAM.

We've filed a document defect to have this documented in release notes.
CSCud99946    NAC release note should say we support SHA-2 certs 

Regards,

Jatin

~Jatin

View solution in original post

3 Replies 3

Jatin Katyal
Cisco Employee
Cisco Employee

Hello Rafael,

SHA-2 signed certificate support was added in 4.7.2 for CAS and CAM.

We've filed a document defect to have this documented in release notes.
CSCud99946    NAC release note should say we support SHA-2 certs 

Regards,

Jatin

~Jatin

Thanks for the confirmation Jatin.  That's what I needed to know.  Bottom line is that I can't use SHA-2 certs on my system running 4.1(8) unless I upgrade to at least 4.7(2).  

Rafael,

If in case you upgrade, go for the latest version.

-Jatin

~Jatin