Hello,
We ran a vulnerability scanning and found that our ICA certificate was using SHA1.
Based on KBs such as sk103840 and sk108252, we determined that to resolve this issue, we would need to renew the ICA certificate to change the hash algorithm to SHA256, as stated in sk158096. Please feel free to correct me on my stance.
However we have some concerns we would like to address:
1. Our ICA certificate's expiry date is on 2027, and as it has not expired yet, Based on sk158096 there shouldnt be any downtime for this renewal process?
2. Our vulnerability scanning detected the vulnerability was detected on the security gateway, however the sk158096 only has the solutions (script) performed on the management server. How can we know whether this solution would be propagated/pushed to the gateway? Were hoping to have a bit of clarification of this process.
We welcome any feedback on our concerns and appreciate your time in reviewing them.
Regards,