주요 콘텐츠로 건너뛰기

Microsoft SHA-2 Policy

User-added image

Microsoft has announced a new policy for Certificate Authorities (CAs) that deprecates the use of the SHA1 algorithm in SSL and code signing certificates, in favor of SHA2. The policy affects CAs who are members of the Windows Root Certificate Program who issue publicly trusted certificates.  It will allow CAs to continue to issue SSL and code signing certificates until January 1 2016, and thereafter issue SHA2 certificates only.

Windows PKI blog, "SHA1 Deprecation Policy". https://docs.microsoft.com/en-us/security-updates/securityadvisories/2017/4010323 , December 12/17/2013

Key Dates:

  • 1 Jan 2016 – CAs must stop issuing SHA1 certificates
  • 1 Jan 2017 – Windows will stop accepting SHA1 SSL certificates
  • 1 Jan 2016 – Windows will stop accepting SHA1 code signing certificates without time stamps

Details:

For SSL certificates, Windows will stop accepting SHA-1 end-entity certificates by January 1, 2017. This means for Windows, a three-year SHA-1 certificate issued after January 1, 2014 won’t work after that date. Same for a two-year SHA-1 certificate issued after January 1, 2015, and a one-year SHA-1 certificate issued after January 1, 2016. It’s time to plan ahead when ordering or renewing your certificates.

For code signing certificates, Windows will stop accepting SHA-1 code signing certificates without time stamps after January 1, 2016.

Internet Explorer and  new versions of Mac OSX, Firefox, Chrome, Opera, Safari, Java and Adobe Acrobat/Reader all support SHA-2

Some enterprises might be running a non-browser application that does not support SHA-2. If you are unaware, you need to do some investigation or testing to see if your system supports SHA-2 and consider your migration plan.

If you have any questions or concerns please contact the Entrust Certificate Services Support department for further assistance:

Hours of Operation:
Sunday 8:00 PM ET to Friday 8:00 PM ET
North America (toll free): 1-866-267-9297
Outside North America: 1-613-270-2680 (or see the list below)
NOTE: Smart Phone users may use the 1-800 numbers shown in the table below.
Otherwise, it is very important that international callers dial the UITF format exactly as indicated. Do not dial an extra "1" before the "800" or your call will not be accepted as an UITF toll free call.

국가 Number
오스트레일리아 0011 - 800-3687-7863
1-800-767-513
오스트리아 00 - 800-3687-7863
벨기에 00 - 800-3687-7863
덴마크 00 - 800-3687-7863
핀란드 990 - 800-3687-7863 (Telecom Finland)
00 - 800-3687-7863 (Finnet)
프랑스 00 - 800-3687-7863
독일 00 - 800-3687-7863
홍콩 001 - 800-3687-7863 (Voice)
002 - 800-3687-7863 (Fax)
아일랜드 00 - 800-3687-7863
이스라엘 014 - 800-3687-7863
이탈리아 00 - 800-3687-7863
일본 001 - 800-3687-7863 (KDD)
004 - 800-3687-7863 (ITJ)
0061 - 800-3687-7863 (IDC)
대한민국 001 - 800-3687-7863 (Korea Telecom)
002 - 800-3687-7863 (Dacom)
말레이시아 00 - 800-3687-7863
네덜란드 00 - 800-3687-7863
뉴질랜드 00 - 800-3687-7863
0800-4413101
노르웨이 00 - 800-3687-7863
싱가포르 001 - 800-3687-7863
스페인 00 - 800-3687-7863
스웨덴 00 - 800-3687-7863 (Telia)
00 - 800-3687-7863 (Tele2)
스위스 00 - 800-3687-7863
대만 00 - 800-3687-7863
영국 00 - 800-3687-7863
0800 121 6078
+44 (0) 118 953 3088