A Replacing Certificate Signed Using MD5 Algorithm with Certificate Signed Using SHA-2 Algorithm
Oracle strongly recommends that you refrain from using a certificate signed with Message Digest 5 Algorithm (MD5), because the security of MD5 algorithm has been compromised. Therefore, you must replace the certificate signed using MD5 algorithm with a certificate signed with Secure Hashing Algorithm 2 (SHA-2). By default, certificates signed using MD5 algorithm are no longer supported in Oracle HTTP Server.
How to Check whether Certificate Signed with MD5 Algorithm is Present in the Wallet?
You can use the orapki utility to display whether your wallet contains a certificate signed with MD5 algorithm.
Removing Certificate Signed with MD5 Algorithm from the Wallet
If MDS is present in your wallet, the signature algorithm name is displayed as MDSwithRSA
. You must replace this certificate with certificate signed using SHA2 algorithm.
Adding Certificate Signed with SHA-2 Algorithm to the Wallet
If you are using CA-signed user certificate that is signed with MD5 algorithm, contact your certificate authority to a get a new user certificate signed with SHA-2 algorithm and import it in to the wallet.
Owner: CN=www.xyx.com, C=IN
Issuer: CN=www.xyx.com, C=IN
Serial number: f689ec6986c70f973138962eb2f0e5f9
Valid from: Wed May 11 04:01:24 PDT 2024 until: Sat Oct 27 04:01:24 PDT 2025
Certificate fingerprints:
MD5: D7:0F:CB:00:A7:04:33:DA:2F:8A:AD:C9:2A:9E:DF:26
SHA1: D4:6C:51:DB:53:B5:F5:C7:60:8D:8B:95:68:E6:B0:5E:E8:00:ED:DF
SHA256: B1:EF:73:98:EA:6A:1A:60:FF:1F:10:89:8C:B8:16:63:71:03:1B:6E:38:D1:2D:AE:E9:BD:3E:13:BE:AF:A0:76
Signature algorithm name: SHA256withRSA
Version: 1
Enabling Support for Certificate Signed with MD5 Algorithm in your 14.1.2.0.0 Oracle HTTP Server Deployment
By default, support of certificate signed with MD5 algorithm has been removed because the security of MD5 algorithm is severely compromised. If you still want to use certificate signed using MD5 algorithm, you can enable the support for a certificate signed with MD5 algorithm by following the procedure in this section. However, enabling support for certificates signed using MD5 algorithm is not recommended.
- For Standalone Oracle HTTP Server deployment:
- For Managed Oracle HTTP Server deployment: