certificate problem
Signed with SHA-1 (deprecated)
What's going on
SHA-1 signatures can be forged with realistic effort and have been rejected by browsers since 2017. A SHA-1 certificate in active use today is either very old or issued by badly outdated tooling.
How to fix it
Reissue the certificate with SHA-256. If an internal CA issued it, that CA's configuration needs updating (and possibly the CA certificate itself reissuing). Old appliances that can only do SHA-1 need a firmware update or replacement.
New to certificates? Start with the guide: How to read an SSL certificate.
Check your certificate for this problem
The decoder detects it automatically — locally, with nothing uploaded.
Open the certificate decoder →