Sentry CA 3.5 does not support mixed-digest CA chains
Originally Published: 2001-07-23
Article Number
Applies To
TechNote 0104
Issue
When creating (or resigning) CA's for a hierarchy it is important to specify the issuer as the parent CA in the hierarchy. It is also important that the digest type throughout the entire PKI be the same.
Mixed type certificate chains are not supported in Sentry CA 3.5. For example, if you set the Root CA to be RSA/MD5 and the Admin CA to be DSA/SHA1, you will in fact create an Admin CA that is DSA/MD5.
Resolution
Related Articles
RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide 3.54KNumber of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager Upgrade Process How to delete old or pending certificate signing requests for RSA Authentication Manager console or virtual host replaceme…
Don't see what you're looking for?