WhyCrashed

certificate problem

Signed with SHA-1 (deprecated)

What's going on

SHA-1 signatures can be forged with realistic effort and have been rejected by browsers since 2017. A SHA-1 certificate in active use today is either very old or issued by badly outdated tooling.

How to fix it

Reissue the certificate with SHA-256. If an internal CA issued it, that CA's configuration needs updating (and possibly the CA certificate itself reissuing). Old appliances that can only do SHA-1 need a firmware update or replacement.

New to certificates? Start with the guide: How to read an SSL certificate.

Check your certificate for this problem

The decoder detects it automatically — locally, with nothing uploaded.

Open the certificate decoder →