Score:0

created a new offline root CA . All of the certs that are based off of this ca cert root for fail, when used on non Microsoft systems

ie flag

The reason it is failing is because I used a Microsoft example as the the policy.inf file. I edited the file to match my data but I left in the line: AlternateSignatureAlgorithm=1

How do I fix this without rebuilding a whole new ca?

The root ca cert has to be re-issued based off of a new capolicy.inf file and then all of the certs that are based off of the old root cert need to be re-issued.

I have changed the capolicy.inf file and requested a new cert with new keys and the new ca root cert still has the Signature Algorithm set to RSASSA-PSS

If someone could give me the step by step on how to re-issue the new root cert with the correct Signature Algorithm that would be great.

Thanks in advance for any help.

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.