Oct 26 2018

T83-2016: BIOVIA recommends updating SHA-1 type SSL Certificates

Workbook

In order to verify un-tampered network traffic, SSL certificates create hash representations of network content and compare the source value to the destination value. The industry has deemed that a common hash-creation algorithm called SHA-1 is no longer secure. The industry standard has moved to SHA-2, and many of today’s common web browser suppliers have reported that beginning on January 1, 2017, these types of certificates will no longer be considered valid/secure.

 

If deployments of BIOVIA solutions continue to use SHA-1 certificates after January 1, 2017, ramifications will vary by BIOVIA product, browser type, and environment. BIOVIA is not able to predict with 100% certainty how or if end users of BIOVIA solutions will be affected when using SHA-1 certificates after January 1. However, BIOVIA acknowledges that issues may arise and hence strongly recommends that customers update any SHA-1 certificates as soon as possible.
 


Resolution:

Inspect each of your active certificates to identify if the hashing algorithm is SHA-1. On Windows servers this can be done from IIS Manager > Server Certificates. Open your certificate properties, then go to the Details tab of the Properties dialog, and inspect the ‘Signature Hashing Algorithm’ value.

 

If any of your certificates are SHA-1 then contact BIOVIA Support as soon as possible. Also contact the agency that provides your SSL certificates and discuss options for updating or replacing your certificates. After updating or replacing your certificates you will need to reconfigure your BIOVIA applications accordingly.