05-21-2016 08:06 AM - edited 02-21-2020 08:49 PM
Hi -
asa5550, image = 8.4.x, Installed sha2 ssl certificate, everything is working fine.
However, when anyconnect client connects to asa, it shows "hashing = sha1". why?
Can someone shed some lights in here please? Thanks
05-21-2016 11:01 AM
Hey Joe,
So you installed the SSL cert and placed in the outside interface?
ssl trust-point my.digicert.trustpoint outside
Also are you testing AnyConnect or WebVPN?
Please proceed to rate and mark as correct the helpful post!
David Castro,
05-21-2016 12:42 PM
Thanks for replying Dave -
Yes, ssl certificate is placed in the outside interface and associated to a trust-point.
Yes, tested using anyconnect and webvpn. Both show hashing = sha1
Thanks
05-21-2016 07:11 PM
Hey Jose,
Can you give me the DNS name?, is this a cert renewal or the first time you install the cert? when you see the Identity cert, you can see the SHA256 protocol? is there any other cert installed? Did you test on Chrome, IE and Firefox?
Thanks,
David Castro,
05-22-2016 02:50 AM
You are mixing two independent security elements here:
05-22-2016 09:31 AM
Hi -
I am not talking about "encryption" SHA256, i am concerning about "hashing" SHA1 as shown below.
Username : xxxxxxxxx Index : 25255
Assigned IP : xxxxxxxxx Public IP : xxxxxxxxx
Protocol : AnyConnect-Parent SSL-Tunnel
License : AnyConnect Premium, AnyConnect for Mobile
Encryption : AES256 AES256 Hashing : SHA1 SHA1
Bytes Tx : 214685397 Bytes Rx : 38214662
Group Policy : xxxxxxxxx Tunnel Group : xxxxxxxxx
as far as i know, Sha2 is supported from 8.2.5 onwards, check the release notes below:
http://www.cisco.com/c/en/us/td/docs/security/asa/roadmap/asa_new_features.html
------Snippet from the link above-----
SSL SHA-2 digital signature
You can now use of SHA-2 compliant signature algorithms to authenticate SSL VPN connections that use digital certificates. Our support for SHA-2 includes all three hash sizes: SHA-256, SHA-384, and SHA-512. SHA-2 requires AnyConnect 2.5(1) or later (2.5(2) or later recommended). This release does not support SHA-2 for other uses or products.
My asa is running 8.4.x, anyconnect client is 3.x, so SHA2 should be supported, but the "hashing" is still showing up as SHA1. That is my concern.
05-22-2016 10:35 AM
i am concerning about "hashing" SHA1 as shown below.
That's exactly what I'm talking about. SHA256 in the certificate is supported to authenticate the tunnel. That's all that is supported. It is not supported to protect the tunnel for integrity.
05-22-2016 01:29 PM
Thanks for quick response.
SHA256 in the certificate is supported to authenticate the tunnel. That's all that is supported. It is not supported to protect the tunnel for integrity.
Are you saying "hashing" is not used to protect data integrity? Can you share a url or link please as i am very confused now.
05-22-2016 02:53 PM
I think i found my answer in below link, thanks
https://supportforums.cisco.com/discussion/12752311/sha256-algorithm-not-showing-asa-ver-91
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide