Which signature algorithms are supported when re-signing server certificates?
Originally Published: 2001-07-11
Article Number
Applies To
Keon Certificate Authority
TechNote 0192
Issue
Which signature algorithms are supported when re-signing a server certificate?
Resolution
The webserver certificates used for client SSL (ie. to a user's web browser) are stored in the file system as the adminServer.cert, enrollDSSServer.cert and enrollServer.cert. The enrollDSSServer certificate must be signed by a DSA CA. The other certificates can be signed with either RSA or DSA.
Note : for supporting all versions of Internet Explorer, you should use RSA as your
signature algorithm. Versions of MSIE prior to 4.0 with service pack 4.0 do
not support DSA signing (see the solution "Configuring MSIE 4.x to support DSA CAs").
For Sentry CA 3.7, certificate files are automatically backed up to <file>.bak in the certs directory when re-signing. If you experience a problem after re-signing, restore the backed up certificate file and re-start Sentry.
Related Articles
Re-enrolling for a certificate 6Number of Views User Event Monitor Messages for Cloud Access Service (20601 - 38000) 341Number of Views Authentication failed error when attempting to log in to the RSA SecurID Access Cloud Administration Console 87Number of Views Entitlements manually added when an Application has 'Complete Manual Activity Before Collection' enabled do not show in th… 215Number of Views Disaster recovery - Re-imaging a RC 96Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process
Don't see what you're looking for?