Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

PENDING SHA-1 in root CA for SCCM CB ssetup?

  • Thread starter Thread starter eavenhuang
  • Start date Start date
  • Replies Replies 1
  • Views Views 1K

eavenhuang

Member
Messages
23
Solutions
3
Reaction score
0
Points
1
SHA-1 in root CA for SCCM CB ssetup?

I noticed that our root CA (hosted in DC) is still using SHA-1. Currently we are running into HTTPS issue.
I'm wondering
Will Sha-1 still support SCCM Current Branch, or this could be the root cause that client PC can't sign PKI?
If SHA-2 is a must, how can I upgrade to SHA-2 without impacting our DC? no reboot if possible.
I guess even if I used a member server to install a new CA role, it can't host SHA-256 directly? if it still used the root CA.
Thanks.
 
Last edited by a moderator:
SHA-1 is completely deprecated and is insecure, so personally I wouldn't suggest you to use it. You can hire a PKI consultant to upgrade to SHA-2.
 
Back
Top