{"id":4743,"date":"2025-12-07T14:46:50","date_gmt":"2025-12-07T14:46:50","guid":{"rendered":"https:\/\/geekmungus.co.uk\/?p=4743"},"modified":"2025-12-07T14:46:50","modified_gmt":"2025-12-07T14:46:50","slug":"convert-the-certificate-for-microsoft-windows-server-2016","status":"publish","type":"post","link":"https:\/\/geekmungus.co.uk\/?p=4743","title":{"rendered":"Convert the Certificate for Microsoft Windows Server 2016"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Microsoft Windows 2016 does not support the newer encryption ciphers used by default by EJBCA (AES256-SHA256), therefore we need to generate a version of the certificate using the earlier encryption cipher type, i.e. TripleDES-SHA1 which is what is supported by the earlier version of Microsoft Windows, namely Server 2016.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-CheckEncryptionCiphersUsed\">Check Encryption Ciphers Used<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Firstly get the pkcs12 certificate onto a machine with OpenSSL installed, the run the following:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>openssl pkcs12 -in old.pfx -info -nodes<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Enter the&nbsp;<strong>Import Password<\/strong>, if present.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Within the output you&#8217;ll see that it is indeed using&nbsp;<strong>AES256-SHA256<\/strong>&nbsp;which is not suitable for Windows 2016.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"636\" height=\"118\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-3.png\" alt=\"\" class=\"wp-image-4744\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-3.png 636w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-3-300x56.png 300w\" sizes=\"auto, (max-width: 636px) 100vw, 636px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"553\" height=\"139\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-4.png\" alt=\"\" class=\"wp-image-4745\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-4.png 553w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-4-300x75.png 300w\" sizes=\"auto, (max-width: 553px) 100vw, 553px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-ConvertPKCS12(PFX)FormatfromAES256-SHA256toTripleDES-SHA1\">Convert PKCS12 (PFX) Format from AES256-SHA256 to TripleDES-SHA1<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We now convert the certificate&#8217;s encryption cipher type, we need to do this via an intermediate step converting it into PEM format then back to PKCS12 (PFX).<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>openssl pkcs12 -in email.p12 -out legacy-email.pem -nodes<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Enter the&nbsp;<strong>Import Password<\/strong>, if present.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Convert the encryption type from&nbsp;<strong>AES256-SHA256&nbsp;<\/strong>to<strong>&nbsp;TripleDES-SHA1&nbsp;<\/strong>with:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>openssl pkcs12 -export -inkey legacy-email.pem -in legacy-email.pem -out legacy-email.p12 -macalg sha1 -keypbe PBE-SHA1-3DES -certpbe PBE-SHA1-3DES<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Enter Export Password (and confirm). You&#8217;ll need this later on when importing the certificate to the server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You now have a new file called&nbsp;<strong>legacy-email.p12<\/strong>&nbsp;which has the same certificate but with the correct encryption cipher type.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-CheckEncryptionCiphersofNewCertificateFile\">Check Encryption Ciphers of New Certificate File<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We now need to check the Certificate Cipher has been exported in the new certificate file to the legacy type, i.e.&nbsp;<strong>TripleDES-SHA1<\/strong>, so we run:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>openssl pkcs12 -in legacy-email.p12 -info -nodes<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">And now we can see the encryption type in the new certificate file is:\u00a0<strong>TripleDES-SHA1<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"588\" height=\"182\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-5.png\" alt=\"\" class=\"wp-image-4746\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-5.png 588w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-5-300x93.png 300w\" sizes=\"auto, (max-width: 588px) 100vw, 588px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"628\" height=\"163\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-6.png\" alt=\"\" class=\"wp-image-4747\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-6.png 628w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-6-300x78.png 300w\" sizes=\"auto, (max-width: 628px) 100vw, 628px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">We&#8217;re all set to continue now, obviously you&#8217;ll nee to be using this newly exported PKCS12 (PFX) certificate file instead!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Although this is covered in Step 3, you&#8217;ll see something like this when importing an unsupported certificate on Windows Server (2016) and then what it looks like if it works as expected.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"175\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-7-1024x175.png\" alt=\"\" class=\"wp-image-4748\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-7-1024x175.png 1024w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-7-300x51.png 300w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-7-768x132.png 768w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-7.png 1454w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Windows 2016 does not support the newer encryption ciphers used by default by EJBCA (AES256-SHA256), therefore we need to generate a version of the certificate using the earlier encryption cipher type, i.e. TripleDES-SHA1 which is what is supported by the earlier version of Microsoft Windows, namely Server 2016. Check Encryption Ciphers Used Firstly get &#8230; <a title=\"Convert the Certificate for Microsoft Windows Server 2016\" class=\"read-more\" href=\"https:\/\/geekmungus.co.uk\/?p=4743\" aria-label=\"Read more about Convert the Certificate for Microsoft Windows Server 2016\">Read more<\/a><\/p>\n","protected":false},"author":4,"featured_media":4282,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":["post-4743","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-windows"],"_links":{"self":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4743","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4743"}],"version-history":[{"count":1,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4743\/revisions"}],"predecessor-version":[{"id":4750,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4743\/revisions\/4750"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/media\/4282"}],"wp:attachment":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4743"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4743"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4743"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}