Support for ACcess Manager server certificate with SHA256 signature algorithm

  • 7010832
  • 25-Sep-2012
  • 25-Sep-2012

Environment

NetIQ Access Manager 3.2
NetIQ Access Manager 3.2 Identity Server
NetIQ Access Manager 3.2 Admin COnsole
NetIQ Access Manager 3.2 Access Gateway
NetIQ Access Manager 3.2 SSLVPN server

Situation

The Access Manager documentation https://www.netiq.com/documentation/novellaccessmanager32/adminconsolehelp/data/certificates.html clearly states that the only signature algorithms supported  on server certificates used by all Access Manager components are SHA-1, MD-2, or MD-5. Is there any support for server certificates with the SHA2 signature algorithms e.g. SHA256?

Resolution

Server certificates used by all Access Manager components using the SHA256 signature algorithms will work fine with the product and are supported. The only limitation lies with the fact that the iManager certificate plugins do not allow you to create any certificates outside the default SHA algorithm. Importing 3rd party server certs with this signature algorithm is the only option available.