cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2371
Views
0
Helpful
1
Replies

SHA-1-based Signature in TLS/SSL Server X.509 Certificate- ISE

st92
Cisco Employee
Cisco Employee

Any idea how to resolve the vulnerability SHA-1-based Signature in TLS/SSL Server X.509 Certificate in ISE?

1 Reply 1

hslai
Cisco Employee
Cisco Employee

A fresh install of ISE uses a self-signed SHA-1 certificate. CSCuv88163 is a known enhancement on this. We may easily generate a self-signed SHA-2 certificate or a CSR and have an external PKI to sign and provide a SHA-2 certificate to replace the SHA-1 one.