I've been upgrading my FreeIPA systems since v4.84, now running v4.12.2 without 
issue.  Seeing the following warnings, I wonder if I should remove these 
deprecated algorithms manually or if the next FreeIPA upgrade should handle 
that.  If so, what would be the appropriate Fedora 41 equivalent for these 
configuration settings?  Would I reference 
https://github.com/dogtagpki/pki/blob/master/base/ca/shared/conf/CS.cfg, for 
example?


pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/CS.cfg:386: 
ca.Policy.rule.SigningAlgRule.algorithms=MD5withRSA,MD2withRSA,SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caUUIDdeviceCert.cfg:96: 
policyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/AdminCert.cfg:83: 
policyset.adminCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caInternalAuthOCSPCert.cfg:68: 
policyset.ocspCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caUserCert.cfg:98: 
policyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caRACert.cfg:82: 
policyset.raCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caAgentFileSigning.cfg:83: 
policyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caRARouterCert.cfg:82: 
policyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caUserSMIMEcapCert.cfg:98: 
policyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caRAagentCert.cfg:92: 
policyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caRAserverCert.cfg:82: 
policyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caRouterCert.cfg:82: 
policyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caSignedLogCert.cfg:68: 
policyset.caLogSigningSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caCrossSignedCACert.cfg:79: 
policyset.caCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caSigningUserCert.cfg:82: 
policyset.signingCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caDirBasedDualCert.cfg:92: 
policyset.encryptionCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caDirBasedDualCert.cfg:164: 
policyset.signingCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caDirBasedDualCert.cfg:168: 
policyset.signingCertSet.9.default.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caDirPinUserCert.cfg:96: 
policyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caDirUserCert.cfg:96: 
policyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caStorageCert.cfg:76: 
policyset.drmStorageCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caDualCert.cfg:92: 
policyset.encryptionCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caDualCert.cfg:164: 
policyset.signingCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caDualCert.cfg:168: 
policyset.signingCertSet.9.default.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caDualRAuserCert.cfg:91: 
policyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caTPSCert.cfg:82: 
policyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caECDualCert.cfg:164: 
policyset.signingCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caIPAserviceCert.cfg:82: 
policyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caInstallCACert.cfg:83: 
policyset.caCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caInternalAuthAuditSigningCert.cfg:77: 
policyset.auditSigningCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caEncUserCert.cfg:92: 
policyset.encryptionCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caInternalAuthDRMstorageCert.cfg:83: 
policyset.drmStorageCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caOtherCert.cfg:82: 
policyset.otherCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caInternalAuthTransportCert.cfg:83: 
policyset.transportCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caJarSigningCert.cfg:83: 
policyset.caJarSigningSet.6.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caTransportCert.cfg:82: 
policyset.transportCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caServerKeygen_DirUserCert.cfg:101: 
policyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC,SHA256withRSA/PSS,SHA384withRSA/PSS,SHA512withRSA/PSS
pkidaemon[3699]: WARNING: Deprecated algorithm in 
/etc/pki/pki-tomcat/ca/profiles/ca/caServerKeygen_UserCert.cfg:97: 
policyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC,SHA256withRSA/PSS,SHA384withRSA/PSS,SHA512withRSA/PSS

-- 
Anthony - https://messinet.com



-- 
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to